SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-2414

Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV…

LOW 2.6EPSS 3.39%

Does this matter?

Lower severity and a low EPSS score (3.39%). Track it; it rarely justifies an emergency change on its own.

Description

Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the currently rendering page and referenced objects to be deleted.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
EPSS
3.39% probability · 88th percentile
CISA KEV
Not listed
Affected
xpcom/xpcom
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.