CVE-2005-2414
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV…
Does this matter?
Lower severity and a low EPSS score (3.39%). Track it; it rarely justifies an emergency change on its own.
Description
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 3.39% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- xpcom/xpcom
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112199282029269&w=2
- http://securitytracker.com/id?1014548
- http://securitytracker.com/id?1014550
- http://www.gulftech.org/?node=research&article_id=00091-07212005
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21472
- http://marc.info/?l=bugtraq&m=112199282029269&w=2
- http://securitytracker.com/id?1014548
- http://securitytracker.com/id?1014550
- http://www.gulftech.org/?node=research&article_id=00091-07212005
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21472
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.