PT-2006-2289 · Mozilla · Firefox

Michal Zalewski

·

Published

2006-03-19

·

Updated

2024-08-07

·

CVE-2006-1273

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 1.0.7 through 1.5.0.1
Description The issue allows remote attackers to cause a denial of service via an HTML tag with a large number of script action handlers such as onload and onmouseover. This triggers the crash when the user views the page source. However, it has been disputed by Red Hat and confirmed by Mozilla that this is not an issue in Firefox itself, but rather likely caused by the IE Tab extension.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2006-1273

Affected Products

Firefox