CVE-2008-4324

Firefox 3.0.2-3.0.3 - Denial of Service via Event Dispatcher Null Pointer Dereference

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4324. PoCs published by Aditya K Sood.

AI-analyzed exploit summary This exploit triggers a null pointer dereference in Mozilla Firefox by dispatching multiple UI events, leading to a denial of service (DoS) crash. The PoC uses JavaScript to create and dispatch events in loops, causing an unhandled exception.

Description

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Aditya K Sood · htmldoswindows
https://www.exploit-db.com/exploits/6614

This exploit triggers a null pointer dereference in Mozilla Firefox by dispatching multiple UI events, leading to a denial of service (DoS) crash. The PoC uses JavaScript to create and dispatch events in loops, causing an unhandled exception.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Mozilla Firefox 3.0.3 (1.9.0 Branch)
No auth needed
Prerequisites: Victim must visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Various Sources x_refsource_misc
http://www.secniche.org/moz303.html
Exploit third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4321
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32040
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31476
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6614
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/496807/100/0/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/496846/100/0/threaded

Scores

EPSS 0.0892
EPSS Percentile 94.6%

Details

CWE
CWE-399
Status published
Products (1)
mozilla/firefox 3.0.3
Published Sep 29, 2008
Tracked Since Feb 18, 2026