CVE-2004-1200: Medium severity mozilla firefox vulnerability
Published Dec 15, 2004
·Updated
Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
Affected Software
9 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=preview_release
Event History
Dec 15, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1200?
CVE-2004-1200 is categorized as a denial of service vulnerability that can result in application crashes.
2
Which versions of Firefox are affected by CVE-2004-1200?
CVE-2004-1200 affects Firefox versions 0.8, 0.9, 0.10, and their specific subversions.
3
How do I fix CVE-2004-1200?
To fix CVE-2004-1200, upgrade to a version of Firefox that is not affected by this vulnerability.
4
What type of attack does CVE-2004-1200 describe?
CVE-2004-1200 describes an attack that causes denial of service through excessive memory consumption via nested arrays in JavaScript.
5
Can CVE-2004-1200 exploit other components of Mozilla?
CVE-2004-1200 is specific to Firefox and does not directly exploit other Mozilla products.