Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.
Name | Vendor | Start Version | End Version |
---|---|---|---|
K-meleon | K-meleon_project | 1.0.1 (including) | 1.0.1 (including) |
Firefox | Mozilla | 0.8 (including) | 0.8 (including) |
Firefox | Mozilla | 0.9 (including) | 0.9 (including) |
Firefox | Mozilla | 0.9-rc (including) | 0.9-rc (including) |
Firefox | Mozilla | 0.9.1 (including) | 0.9.1 (including) |
Firefox | Mozilla | 0.9.2 (including) | 0.9.2 (including) |
Firefox | Mozilla | 0.9.3 (including) | 0.9.3 (including) |
Firefox | Mozilla | 0.10 (including) | 0.10 (including) |
Firefox | Mozilla | 0.10.1 (including) | 0.10.1 (including) |
Firefox | Mozilla | 1.0 (including) | 1.0 (including) |
Firefox | Mozilla | 1.0.1 (including) | 1.0.1 (including) |
Firefox | Mozilla | 1.0.2 (including) | 1.0.2 (including) |
Firefox | Mozilla | 1.0.3 (including) | 1.0.3 (including) |
Firefox | Mozilla | 1.0.4 (including) | 1.0.4 (including) |
Firefox | Mozilla | 1.0.5 (including) | 1.0.5 (including) |
Firefox | Mozilla | 1.0.6 (including) | 1.0.6 (including) |
Firefox | Mozilla | 1.0.7 (including) | 1.0.7 (including) |
Firefox | Mozilla | 1.0.8 (including) | 1.0.8 (including) |
Firefox | Mozilla | 1.5 (including) | 1.5 (including) |
Firefox | Mozilla | 1.5-beta1 (including) | 1.5-beta1 (including) |
Firefox | Mozilla | 1.5-beta2 (including) | 1.5-beta2 (including) |
Firefox | Mozilla | 1.5.0.1 (including) | 1.5.0.1 (including) |
Firefox | Mozilla | 1.5.0.2 (including) | 1.5.0.2 (including) |
Firefox | Mozilla | 1.5.0.3 (including) | 1.5.0.3 (including) |
Firefox | Mozilla | 1.5.0.4 (including) | 1.5.0.4 (including) |
Firefox | Mozilla | 1.5.0.5 (including) | 1.5.0.5 (including) |
Firefox | Mozilla | 1.5.0.6 (including) | 1.5.0.6 (including) |
Navigator | Netscape | 8.1 (including) | 8.1 (including) |
Red Hat Enterprise Linux 3 | RedHat | seamonkey-0:1.0.5-0.1.el3 | * |
Red Hat Enterprise Linux 4 | RedHat | firefox-0:1.5.0.7-0.1.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | devhelp-0:0.10-0.4.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | seamonkey-0:1.0.5-0.1.el4 | * |
Red Hat Enterprise Linux 4 | RedHat | thunderbird-0:1.5.0.7-0.1.el4 | * |
Firefox | Ubuntu | dapper | * |
Firefox-3.0 | Ubuntu | devel | * |
Firefox-3.0 | Ubuntu | gutsy | * |
Lightning-sunbird | Ubuntu | devel | * |
Lightning-sunbird | Ubuntu | gutsy | * |
Midbrowser | Ubuntu | devel | * |
Midbrowser | Ubuntu | gutsy | * |
Mozilla-thunderbird | Ubuntu | dapper | * |
Mozilla-thunderbird | Ubuntu | edgy | * |
Mozilla-thunderbird | Ubuntu | feisty | * |
Xulrunner | Ubuntu | devel | * |
Xulrunner | Ubuntu | edgy | * |
Xulrunner | Ubuntu | feisty | * |
Xulrunner | Ubuntu | gutsy | * |