First published: Thu Nov 08 2007(Updated: )
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =2.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5896 is classified as a denial of service vulnerability affecting Mozilla Firefox 2.0.0.9, which can lead to CPU consumption and crashing.
To fix CVE-2007-5896, update Mozilla Firefox to a version later than 2.0.0.9 that addresses this vulnerability.
CVE-2007-5896 affects Mozilla Firefox version 2.0.0.9.
CVE-2007-5896 allows remote attackers to cause denial of service attacks through a malicious iframe with specific JavaScript manipulations.
While CVE-2007-5896 is not classified as critical, it poses a significant risk as it can disrupt user experience by causing the browser to crash.