Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Camino | Mozilla | 0.8.4 (including) | 0.8.4 (including) |
Firefox | Mozilla | 1.0.4 (including) | 1.0.4 (including) |
Mozilla | Mozilla | 1.7.8 (including) | 1.7.8 (including) |
Red Hat Enterprise Linux 4 | RedHat | firefox-0:1.0.6-1.4.1 | * |
Red Hat Enterprise Linux 4 | RedHat | devhelp-0:0.9.2-2.4.6 | * |
Firefox-3.0 | Ubuntu | devel | * |
Firefox-3.0 | Ubuntu | gutsy | * |
Lightning-sunbird | Ubuntu | devel | * |
Lightning-sunbird | Ubuntu | gutsy | * |
Midbrowser | Ubuntu | devel | * |
Midbrowser | Ubuntu | gutsy | * |
Mozilla | Ubuntu | edgy | * |