Lucene search

K
mozillaMozilla FoundationMFSA2006-07
HistoryFeb 01, 2006 - 12:00 a.m.

Read beyond buffer while parsing XML — Mozilla

2006-02-0100:00:00
Mozilla Foundation
www.mozilla.org
14

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

EPSS

0.727

Percentile

98.1%

An upgrade in the XML parser introduced a bug that could read beyond the end of the buffer, often causing a crash. We don’t know if this could be exploited to incorporate private data into the DOM of an XML document, but could be a privacy risk if so. Firefox 1.0, Thunderbird 1.0 and Mozilla Suite 1.7 are not affected.

Affected configurations

Vulners
Node
mozillafirefoxRange<1.5.0.1
OR
mozillaseamonkeyRange<1
OR
mozillathunderbirdRange<1.5.0.2
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

EPSS

0.727

Percentile

98.1%