evilfingers.com
http://evilfingers.com/advisory/Firefox_User_Interface_Null_Pointer_Dereference_Dispatcher_Crash_n_Remote_DoS.php CVE-2008-4324
Mozilla Firefox 3.0.3 - User Interface Null Pointer Dereference Crash
Record summary
CVE-2008-4324 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Firefox 3.0.3 - User Interface Null Pointer Dereference CrashExploitDB exploitby Aditya K SoodNot analyzed1 file
References
1032040Third-party advisory
http://secunia.com/advisories/32040 4321Third-party advisory
http://securityreason.com/securityalert/4321 secniche.org
http://www.secniche.org/moz303.html secniche.org
http://www.secniche.org/moz303/index.html 20080928 Advisory: Mozilla Firefox User Interface Null Pointer Dereference Dispatcher Crash and Remote Denial of Service.mailing list
http://www.securityfocus.com/archive/1/496807/100/0/threaded 20080930 Re: Advisory: Mozilla Firefox User Interface Null Pointer Dereference Dispatcher Crash and Remote Denial of Service.mailing list
http://www.securityfocus.com/archive/1/496846/100/0/threaded 31476vdb entry
http://www.securityfocus.com/bid/31476 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4324 6614exploit
https://www.exploit-db.com/exploits/6614