Vulnerabilities > CVE-2009-2953 - Resource Management Errors vulnerability in Mozilla Firefox

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
mozilla
CWE-399
exploit available

Summary

Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionMozilla Firefox 3.0.5 location.hash Remote Crash Exploit. CVE-2008-5715,CVE-2009-2953. Dos exploit for windows platform
fileexploits/windows/dos/7554.pl
idEDB-ID:7554
last seen2016-02-01
modified2008-12-23
platformwindows
port
published2008-12-23
reporterJeremy Brown
sourcehttps://www.exploit-db.com/download/7554/
titleMozilla Firefox 3.0.5 location.hash Remote Crash Exploit
typedos