IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reloaded.html page in a chrome:// URI. Some third-party researchers claim that they are unable to reproduce this vulnerability.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/434280/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26540 | vdb entry |
http://www.securityfocus.com/archive/1/434519/100/0/threaded | mailing list |