5
CVSSv2

CVE-2005-4720

Published: 31/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Mozilla Firefox 1.0.7 and previous versions on Linux allows remote malicious users to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, leading to an infinite loop of widget resizes and a corresponding large number of function calls on the stack.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 1.0.6

mozilla firefox 1.0.7

Exploits

source: wwwsecurityfocuscom/bid/15015/info Mozilla Firefox is prone to a remote denial of service vulnerability The vulnerability presents itself when an affected browser handles a specially crafted IFRAME A successful attack may result in crashing the application, or consuming excessive CPU and memory resources of computers running t ...