Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affected.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade dev-libs/nss.Upgrade www-client/icecat.Upgrade www-client/firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner. | Oct 30, 2017 | May 29, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub