CVE-2007-5896
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://osvdb.org/45296
- http://www.0x000000.com/index.php?i=467&bin=111010011
- http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2007-11/msg00094.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38233
- http://osvdb.org/45296
- http://www.0x000000.com/index.php?i=467&bin=111010011
- http://www.derkeiler.com/Mailing-Lists/Full-Disclosure/2007-11/msg00094.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38233
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.