Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/438365/100/100/threaded | mailing list |
http://www.securityfocus.com/archive/1/439064/100/100/threaded | mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26898 | vdb entry |
http://www.securityfocus.com/archive/1/438144/100/100/threaded | mailing list |