Back

MEDIUM

: Firefox DoS (crash) via crafted web site that triggers memory consumption

Published Jan 7, 2010

Description

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2010
Updated Aug 7, 2024
Reserved Jan 7, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 29, 2009
ENISA EUVD
Assigner mitre
Published Jan 7, 2010
Updated Aug 7, 2024
Exploited since n/a
EUVD-2010-0251