An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
Using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Netsurf | Netsurf-browser | 3.11 (including) | 3.11 (including) |