Lucene search

K
zdiRegenrechtZDI-10-050
HistoryApr 02, 2010 - 12:00 a.m.

Mozilla Firefox nsTreeSelection EventListener Remote Code Execution Vulnerability

2010-04-0200:00:00
regenrecht
www.zerodayinitiative.com
20

EPSS

0.104

Percentile

95.0%

This vulnerability allows remote attackers to execute arbitrary code on software utilizing a vulnerable version of Mozillaโ€™s Firefox. User interaction is required in that the victim must visit a malicious website or be coerced into opening a malicious document. The specific flaw exists within how the application handles particular events for an nsTreeSelection element. Upon execution of a โ€œselectโ€ event the application will access an element without checking to see if itโ€™s been previously freed or not. Successful exploitation can lead to code execution under the context of the application.