Vulnerabilities > CVE-2007-5896 - Resource Management Errors vulnerability in Mozilla Firefox 2.0.0.9

047910
CVSS 7.1 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE

Summary

Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.

Vulnerable Configurations

Part Description Count
Application
Mozilla
1

Common Weakness Enumeration (CWE)

Statements

contributorJoshua Bressers
lastmodified2007-11-19
organizationRed Hat
statementRed Hat does not consider this flaw a security issue. This flaw is not exploitable and can only cause a client to stop responding or crash.