0x000000.com
http://www.0x000000.com/?i=576 CVE-2008-2419
Mozilla Firefox 2.0.0.14 - JSframe Heap Corruption Denial of Service
Record summary
CVE-2008-2419 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox 2.0.0.14 - JSframe Heap Corruption Denial of ServiceExploitDB exploitby 0x000000Not analyzed1 file
References
429318vdb entry
http://www.securityfocus.com/bid/29318 mozilla-firefox-jsframe-code-execution(42589)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42589 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2419