Vulnerabilities > CVE-2008-4324 - Resource Management Errors vulnerability in Mozilla Firefox 3.0.3

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
mozilla
microsoft
CWE-399
exploit available

Summary

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

Vulnerable Configurations

Part Description Count
Application
Mozilla
1
OS
Microsoft
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionMozilla Firefox 3.0.3 User Interface Null Pointer Dereference Crash. CVE-2008-4324. Dos exploit for windows platform
fileexploits/windows/dos/6614.html
idEDB-ID:6614
last seen2016-02-01
modified2008-09-28
platformwindows
port
published2008-09-28
reporterAditya K Sood
sourcehttps://www.exploit-db.com/download/6614/
titleMozilla Firefox 3.0.3 User Interface Null Pointer Dereference Crash
typedos