--------------------------------------------------- Software: Firefox Web Browser Tested: Linux, Windows clients' version 1.5.0.2 Result: Firefox Remote Code Execution and Denial of Service - Vendor contacted, no patch yet. Problem: A handling issue exists in how Firefox handles certain Javascript in js320.dll and xpcom_core.dll regarding iframe.contentWindow.focus(). By manipulating this feature a buffer overflow will occur. Proof of Concept: http://www.securident.com/vuln/ff.txt Credits: splices(splices [dot] org) spiffomatic64(spiffomatic64 [dot] com) Securident Technologies (securident [dot] com) ------------------------------------------------ http://www.securident.com/vuln/ffdos.htm - PoC firefox dos Paste the below code snippet and view it in Firefox for DoS PoC or visit the link above. -DISCLAIMER- splices,spiffomatic64, and securident are not responsible for any of the information contained therein, this is all just for informational purposes only.