[] NeoSense

Mozilla Firefox 1.5.0.2 - 'js320.dll/xpcom_core.dll' Denial of Service (PoC)

Author: splices
type: dos
platform: multiple
port: 
date_added: 2006-04-23 
date_updated:  
verified: 1 
codes: OSVDB-24967;CVE-2006-1993 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comFirefoxSetup1.5.0.2.exe

<!--
---------------------------------------------------
Software:
 Firefox Web Browser
Tested:
 Linux, Windows clients' version 1.5.0.2
Result:
 Firefox Remote Code Execution and Denial of Service - Vendor contacted, no patch yet.
Problem:
 A handling issue exists in how Firefox handles certain Javascript in js320.dll and xpcom_core.dll
regarding iframe.contentWindow.focus().  By manipulating this feature a buffer overflow will occur.
Proof of Concept:
 http://www.securident.com/vuln/ff.txt
Credits:
 splices(splices [dot] org)
 spiffomatic64(spiffomatic64 [dot] com)
 Securident Technologies (securident [dot] com)
------------------------------------------------

http://www.securident.com/vuln/ffdos.htm - PoC firefox dos

 Paste the below code snippet and view it in Firefox for DoS PoC or visit the link above. -->

<textarea cols="0" rows="0" id="x_OtherInfo" name="x_OtherInfo">