The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | * | 41.0.2 (including) |
Firefox | Ubuntu | upstream | * |