Vulnerabilities > CVE-2008-2419 - Resource Management Errors vulnerability in Mozilla Firefox 2.0.0.14

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
mozilla
CWE-399
exploit available

Summary

Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.

Vulnerable Configurations

Part Description Count
Application
Mozilla
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionMozilla Firefox 2.0.0.14 JSframe Heap Corruption Denial of Service Vulnerability. CVE-2008-2419. Dos exploits for multiple platform
idEDB-ID:31817
last seen2016-02-03
modified2008-05-21
published2008-05-21
reporter0x000000
sourcehttps://www.exploit-db.com/download/31817/
titleMozilla Firefox 2.0.0.14 - JSframe Heap Corruption Denial of Service Vulnerability