CVE Database
/

CVE-2009-2975

Back to search

CVE-2009-2975

Published: Aug 27, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.

VendorProductVersions

n/a

n/a

affected
n/a

References

firefox-doclocation-dos(52923)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now