Lucene search

K
zdiAnonymousZDI-06-009
HistoryApr 17, 2006 - 12:00 a.m.

Mozilla Firefox Tag Parsing Code Execution Vulnerability

2006-04-1700:00:00
Anonymous
www.zerodayinitiative.com
12

EPSS

0.972

Percentile

99.9%

This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail. The specific flaw exists within nsHTMLContentSink.cpp, during the parsing of HTML tags as they appear in a specific order. The flaw results in a memory corruption that leads to an attacker controlled function pointer dereference from the stack and eventually execution of arbitrary code.