Summary
The host is installed with Mozilla Firefox browser and is prone to Denial of Service vulnerability.
Impact
Successful remote exploitation will allow attackers to crash application via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.
Impact Level: Application.
Solution
Upgrade to Firefox version 3.5.7
http://www.mozilla.com/en-US/firefox/all.html
Insight
The flaw is due to error in 'nsObserverList::FillObserverArray()' function in 'xpcom/ds/nsObserverList.cpp'
Affected
Mozilla Firefox version prior to 3.5.7 on Windows.
References
Severity
Classification
-
CVE CVE-2010-0220 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities