First published: Mon May 22 2006(Updated: )
IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reloaded.html page in a chrome:// URI. Some third-party researchers claim that they are unable to reproduce this vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ie Tab Ie Tab | =1.0.9 | |
Firefox | =1.5.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2538 is considered to have a high severity due to its potential to cause a denial of service through application crashes.
To mitigate CVE-2006-2538, it is recommended to update the IE Tab plugin to a newer version or uninstall it if not necessary.
CVE-2006-2538 affects the IE Tab 1.0.9 plugin and Mozilla Firefox 1.5.0.3.
CVE-2006-2538 is a denial of service vulnerability due to a null dereference triggered by specific Javascript.
Yes, CVE-2006-2538 can be exploited remotely through user-assisted actions, such as visiting a specially crafted URL.