Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2004-1639

Опубликовано: 26 окт. 2004
Источник: debian
EPSS Низкий

Описание

Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxremovedpackage
iceweaselremovedpackage
mozillaremovedpackage

Примечания

  • This is not a real security issue; it just describes the fact that the Gecko

  • engine of the Mozillae may be lead into a crash if you feed it with large chunks

  • of arbitrary binary data and label it as HTML. As the parsing garbage is displayed

  • during transfer any user will cancel the transfer and if you load it from the

  • hard disc, well than you have "DoSed" yourself, congratulations.

  • It's reproducable with 1.0.2, but I doubt it will ever be "fixed", as HTML parsers

  • generally try to make sense of anything even remotely resembling HTML.

EPSS

Процентиль: 75%
0.00886
Низкий

Связанные уязвимости

nvd
около 21 года назад

Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.

github
больше 3 лет назад

Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.

EPSS

Процентиль: 75%
0.00886
Низкий