vendor:
Firefox
by:
John Page aka hyp3rlinx
5,5
CVSS
MEDIUM
Denial Of Service
N/A
CWE
Product Name: Firefox
Affected Version From: v54.0.1
Affected Version To: v54.0.1
Patch Exists: N/A
Related CWE: N/A
CPE: a:mozilla:firefox
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2017
Firefox v54.0.1 Denial Of Service
Dynamically creating HTML elements IMG,FORM,DIV,P,A,H2,IFRAME,TABLE,TEXTAREA and assigning very long string of junk chars to the 'style.color' property results in Firefox Browser out of memory crash (not tab crash). Tested on Windows 7.
Mitigation:
N/A