First published: Fri May 23 2008(Updated: )
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | =2.0.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2419 has a medium severity rating due to its potential to cause a denial of service or execute arbitrary code.
To fix CVE-2008-2419, users should update to a newer version of Mozilla Firefox that has patched the vulnerability.
CVE-2008-2419 is associated with remote code execution and denial of service attacks through heap corruption.
CVE-2008-2419 specifically affects Mozilla Firefox version 2.0.0.14.
Yes, CVE-2008-2419 can be exploited by manipulating Iframe operations between JavaScript frames.