Upstream information
Description
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.SUSE information
Overall state of this security issue: Resolved
This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.
| CVSS detail | National Vulnerability Database | 
|---|---|
| Base Score | 2.6 | 
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:P | 
| Access Vector | Network | 
| Access Complexity | High | 
| Authentication | None | 
| Confidentiality Impact | None | 
| Integrity Impact | None | 
| Availability Impact | Partial | 
List of released packages
| Product(s) | Fixed package version(s) | References | 
|---|---|---|
| SUSE Linux Enterprise Server 11 SP1 | 
 | Patchnames: SUSE Linux Enterprise Server 11 SP1 GA mozilla-xulrunner190-1.9.0.19-0.1.1 | 
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 03:08:35 2013CVE page last modified: Mon Oct 6 18:15:35 2025
