MEDIUM
: Firefox DoS (crash) via crafted web site that triggers memory consumption
Published Jan 7, 2010
5.0
MEDIUMCVSS 2.0
EPSS 1.46%
Description
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
Affected products
No data.
OR
- ≤ 3.5.6
- 0.1
- 0.2
- 0.3
- 0.4
- 0.5
- 0.6
- 0.6.1
- 0.7
- 0.7.1
- 0.8
- 0.9
- 0.9
- 0.9.1
- 0.9.2
- 0.9.3
- 0.10
- 0.10.1
- 1.0
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.0.5
- 1.0.6
- 1.0.7
- 1.0.8
- 1.4.1
- 1.5
- 1.5
- 1.5
- 1.5.0.1
- 1.5.0.2
- 1.5.0.3
- 1.5.0.4
- 1.5.0.5
- 1.5.0.6
- 1.5.0.7
- 1.5.0.8
- 1.5.0.9
- 1.5.0.10
- 1.5.0.11
- 1.5.0.12
- 1.5.1
- 1.5.2
- 1.5.3
- 1.5.4
- 1.5.5
- 1.5.6
- 1.5.7
- 1.5.8
- 1.8
- 2.0
- 2.0.0.1
- 2.0.0.2
- 2.0.0.3
- 2.0.0.4
- 2.0.0.5
- 2.0.0.6
- 2.0.0.7
- 2.0.0.8
- 2.0.0.9
- 2.0.0.10
- 2.0.0.11
- 3.0
- 3.0.5
- 3.5
- 3.5.2
- 3.5.3
- 3.5.4
- 3.5.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (12)
- http://hg.mozilla.org/mozilla-central/rev/51396f6c9f20 x_refsource_CONFIRMExploit
- http://isc.sans.org/diary.html?storyid=7897 x_refsource_MISCPatch
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:000 vendor-advisoryx_refsource_MANDRIVA
- http://www.mozilla.com/en-US/firefox/3.5.7/releasenotes/ x_refsource_CONFIRMPatch
- https://access.redhat.com/security/cve/CVE-2010-0220 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=507114 x_refsource_CONFIRMExploit
- https://bugzilla.redhat.com/show_bug.cgi?id=579085 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0251 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/55550 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-0220
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8292 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-0220
| Link | Providers | Tags |
|---|---|---|
| http://hg.mozilla.org/mozilla-central/rev/51396f6c9f20 | x_refsource_CONFIRMExploit | |
| http://isc.sans.org/diary.html?storyid=7897 | x_refsource_MISCPatch | |
| http://www.mandriva.com/security/advisories?name=MDVSA-2010:000 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.mozilla.com/en-US/firefox/3.5.7/releasenotes/ | x_refsource_CONFIRMPatch | |
| https://access.redhat.com/security/cve/CVE-2010-0220 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=507114 | x_refsource_CONFIRMExploit | |
| https://bugzilla.redhat.com/show_bug.cgi?id=579085 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2010-0251 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/55550 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-0220 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8292 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2010-0220 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 7, 2010
Updated Aug 7, 2024
Reserved Jan 7, 2010
Link CVE-2010-0220
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2010-0251 Assigner mitre
Published Jan 7, 2010
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2010-0251