Beveiligingsadvies

CVE-2009-2975

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2009-08-27 17:00:00
Laatst bijgewerkt 2024-08-07 06:07:37
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.