CVE-2004-0478

Mozilla - Denial of Service via JavaScript Infinite Loop Form Input

Title source: llm
STIX 2.1

Description

Unknown versions of Mozilla allow remote attackers to cause a denial of service (high CPU/RAM consumption) using Javascript with an infinite loop that continues to add input to a form, possibly as the result of inserting control characters, as demonstrated using an embedded ctrl-U.

References (3)

Core 3
Core References
Vendor Advisory mailing-list x_refsource_mlist
http://lists.immunitysec.com/pipermail/dailydave/2004-May/000587.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16225
Vendor Advisory x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=243540

Scores

EPSS 0.0119
EPSS Percentile 64.5%

Details

CWE
CWE-399
Status published
Products (1)
mozilla/mozilla
Published Jul 07, 2004
Tracked Since Feb 18, 2026