Vulnerability Description
The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 1.5 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://osvdb.org/35135
- http://secunia.com/advisories/25476
- http://secunia.com/advisories/25490
- http://secunia.com/advisories/25533
- http://secunia.com/advisories/25534
- http://secunia.com/advisories/25635
- http://secunia.com/advisories/25647
- http://secunia.com/advisories/25685
- http://secunia.com/advisories/25750
- http://secunia.com/advisories/25858
- http://security.gentoo.org/glsa/glsa-200706-06.xml
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware
- http://www.debian.org/security/2007/dsa-1306
- http://www.debian.org/security/2007/dsa-1308
FAQ
What is CVE-2007-2869?
CVE-2007-2869 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CP...
How severe is CVE-2007-2869?
CVE-2007-2869 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2869?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.