CVE-2008-2014Infinite Loop in Mozilla Firefox

CWE-39922 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.2%
top 20.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 30
Latest updateMay 1

Description

Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-hcmc-w4r8-h827: Mozilla Firefox 32022-05-01

💥Exploits & PoCs

10
Exploit-DB
BSI Advance Hotel Booking System 2.0 - 'booking_details.php Persistent Cross-Site Scripting2019-08-12
Exploit-DB
HP Data Protector A.09.00 - Arbitrary Command Execution2016-05-26
Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)2015-02-27
Exploit-DB
JetAudio 8.1.3 - '.mp4' Crash (PoC)2014-12-12
Exploit-DB
Thomson Reuters Fixed Assets CS 13.1.4 - Local Privilege Escalation2014-12-02

💬Community

2
Bugzilla
CVE-2014-5009 CVE-2014-5008 CVE-2008-7313 nagios: snoopy: incomplete fixes for command execution flaws [epel-all]2014-07-21
Bugzilla
CVE-2014-1943 file: unrestricted recursion in handling of indirect type rules2014-02-17