vendor:
Firefox
by:
hdm
N/A
CVSS
N/A
Code Execution
119
CWE
Product Name: Firefox
Affected Version From: Firefox 1.5.0.0
Affected Version To: Firefox 1.5.0.0
Patch Exists: YES
Related CWE: CVE-2006-0295
CPE: a:mozilla:firefox:1.5.0.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X 10.3, Linux
2006
Firefox location.QueryInterface() Code Execution
This module exploits a code execution vulnerability in the Mozilla Firefox browser. To reliably exploit this vulnerability, we need to fill almost a gigabyte of memory with our nop sled and payload. This module has been tested on OS X 10.3 with the stock Firefox 1.5.0 package.
Mitigation:
Update to the latest version of Firefox