Lucene search

K
zdiAnonymousZDI-09-013
HistoryMar 05, 2009 - 12:00 a.m.

Mozilla Firefox XUL Linked Clones Double Free Vulnerability

2009-03-0500:00:00
Anonymous
www.zerodayinitiative.com
17

EPSS

0.175

Percentile

96.2%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Mozilla Firefox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists during the browsers garbage collection process. When multiple DOM elements are cloned and linked to one another and the browser is reloaded, a memory corruption occurs resulting in a double free. This can be leveraged to execute arbitrary code under the context of the current user.