Back

HIGH

Mozilla buffer overflow in http-index-format parser

Published Nov 13, 2008

Description

The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (37)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 13, 2008
Updated Aug 7, 2024
Reserved Dec 13, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Critical
Public date Nov 12, 2008