<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Firefox 3.0.3 remote null pointer DoS vulnerability in Security</title>
<link>http://www.dslreports.com/forum/r21198202</link>
<description></description>
<language>en</language>
<pubDate>Sun, 06 Dec 2009 02:37:23 EDT</pubDate>
<lastBuildDate>Sun, 06 Dec 2009 02:37:23 EDT</lastBuildDate>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21226032</link>
<description><![CDATA[<A HREF="/useremail/u/686640"><b>EUS</b></A> : nm]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21226032</guid>
<pubDate>Mon, 06 Oct 2008 22:05:13 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21223773</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Firefox 3.0.3 on linux ubuntu crashed too  :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21223773</guid>
<pubDate>Mon, 06 Oct 2008 19:52:14 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21206856</link>
<description><![CDATA[<A HREF="/useremail/u/723836"><b>33591094</b></A> : Your expolit did not crash firefox, on my machines.<br><br>--<br><small>Sig? What Sig?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21206856</guid>
<pubDate>Thu, 02 Oct 2008 20:42:46 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21205826</link>
<description><![CDATA[<A HREF="/useremail/u/782124"><b>BeesTea</b></A> : Thanks!<br><br>Though really,  all the thanks go to  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.  Once again they've let us know about these safer, Open-Source, alternatives to vulnerable software.<br><br>Thanks again  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>,  you've really helped me realize the security of these Open-Source projects like Firefox.  If it weren't for your posts here,  I'd still be using the Microsoft equivalent!<br><small>--<br>Overpower, overcome.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21205826</guid>
<pubDate>Thu, 02 Oct 2008 17:46:55 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21205684</link>
<description><![CDATA[<A HREF="/useremail/u/831732"><b>WeenieBoy</b></A> : Wait your kidding.... no your not. Holy Cow I too never had any idea IE 7 had FOUR TIMES the vulnerabilities than firefox. Man from some of the posts here I would have thought the opposite. Thanks for clearing that up for us BeesTea I for one thank you. I guess the OP may wish to read your links.<br><br>;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21205684</guid>
<pubDate>Thu, 02 Oct 2008 17:26:35 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21205356</link>
<description><![CDATA[<A HREF="/useremail/u/1419052"><b>tomazyk</b></A> : <div class="bquote"><small>said by  BeesTea <A HREF="/useremail/u/782124"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>&raquo;<A HREF="http://secunia.com/advisories/product/19089/" >secunia.com/advisories/product/19089/</A><br><br>&raquo;<A HREF="http://secunia.com/advisories/product/12366/" >secunia.com/advisories/product/12366/</A><br><br>Wow! I had no idea Microsoft Internet Explorer 7 had over <b>four times</b> the vulnerabilities as this Open-Source solution. With 32% of the reported vulnerabilities un-patched!  The worst of which is rated <b>moderately critical</b>!!.<br><br> </div>Thanks for that info. I knew IE has un-patched vulnerabilities but never thought there were so many.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21205356</guid>
<pubDate>Thu, 02 Oct 2008 16:20:51 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer remote DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21204873</link>
<description><![CDATA[<A HREF="/useremail/u/1181003"><b>rcdailey</b></A> : I can confirm that it will not crash Firefox 3.0.3 if NoScript is installed.  I did not allow the page in NoScript, because I already knew it was dangerous ;-)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21204873</guid>
<pubDate>Thu, 02 Oct 2008 15:02:07 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21204430</link>
<description><![CDATA[<A HREF="/useremail/u/1432955"><b>Cabal</b></A> : <div class="bquote"><small>said by  BeesTea <A HREF="/useremail/u/782124"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>For a second, I was relieved to see that it wasn't Microsoft Internet Explorer 7 affected. That relief was short lived though. Your post about this Open-Source web browser made me compare the security track records of my version of Microsoft Internet Explorer and this Open-Source solution. <br><br>&raquo;<A HREF="http://secunia.com/advisories/product/19089/" >secunia.com/advisories/product/19089/</A><br><br>&raquo;<A HREF="http://secunia.com/advisories/product/12366/" >secunia.com/advisories/product/12366/</A></div>Good info, thanks for the heads up.<br><small>--<br>Why did Obama sue Citibank under the CRA to <A HREF="http://iusbvision.wordpress.com/2008/09/30/obama-sued-citibank-under-cra-to-force-it-to-make-bad-loans/">force it to make bad loans</a>?</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21204430</guid>
<pubDate>Thu, 02 Oct 2008 14:00:09 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21204256</link>
<description><![CDATA[<A HREF="/useremail/u/782124"><b>BeesTea</b></A> : Wow, thanks for pointing this vulnerability out!<br><br>For a second, I was relieved to see that it wasn't Microsoft Internet Explorer 7 affected. That relief was short lived though. Your post about this Open-Source web browser made me compare the security track records of my version of Microsoft Internet Explorer and this Open-Source solution. <br><br>&raquo;<A HREF="http://secunia.com/advisories/product/19089/" >secunia.com/advisories/product/19089/</A><br><br>&raquo;<A HREF="http://secunia.com/advisories/product/12366/" >secunia.com/advisories/product/12366/</A><br><br>Wow! I had no idea Microsoft Internet Explorer 7 had over <b>four times</b> the vulnerabilities as this Open-Source solution. With 32% of the reported vulnerabilities un-patched!  The worst of which is rated <b>moderately critical</b>!!.<br><br>Thanks so much for this great thread. Had this issue not been brought to my attention by your informative post, I might still be planning to continue my use of Internet Explorer. There will be none of that for me though, I'm moving to this Open-Source browser. It looks to be the safest by far!<br><br>Those open-source guys really owe you, you might be their best advertiser!<br><br>Thanks  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> !<br><small>--<br>Overpower, overcome.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21204256</guid>
<pubDate>Thu, 02 Oct 2008 13:34:12 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21203067</link>
<description><![CDATA[<A HREF="/useremail/u/274243"><b>GILXA1226</b></A> : doesn't affect anything before 3.0.3... kind of pointless if you ask me.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21203067</guid>
<pubDate>Thu, 02 Oct 2008 10:08:25 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21200733</link>
<description><![CDATA[<A HREF="/useremail/u/698374"><b>Elite</b></A> : Yeah, considering this is just a DoS, there isn't much to worry about in terms of it being an actual "security threat" to anybody.<br><br>Now if you could get it to run shellcode... that's another story. This would actually pose a problem, considering you could exploit the said vulnerability and make FF run whatever payload you'd like.<br><small>--<br>QUAD!!!!</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21200733</guid>
<pubDate>Wed, 01 Oct 2008 20:12:24 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21199578</link>
<description><![CDATA[<A HREF="/useremail/u/831732"><b>WeenieBoy</b></A> : It does not affect version 2 series. used 2.0.0.17. I agree with both SUMware and Alphanet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21199578</guid>
<pubDate>Wed, 01 Oct 2008 16:44:54 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21199391</link>
<description><![CDATA[<A HREF="/useremail/u/545660"><b>Alphanet</b></A> : So, you go to a web site and it crashes your browser, if you go back it crashes it again. After a few tries you reliase that if you don't go back to the site again it will stop your browser crashing.<br><br>That is a minor bug,it is not a high severity security issue.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21199391</guid>
<pubDate>Wed, 01 Oct 2008 16:06:41 EDT</pubDate>
</item>

<item>
<title>Re: Firefox 3.0.3 remote null pointer remote DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21198278</link>
<description><![CDATA[<A HREF="/useremail/u/634007"><b>SUMware</b></A> : <div class="bquote"><small>said by  matunga <A HREF="/useremail/u/847301"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>      :</small><br><br>(it will crash your firefox):<br> </div>With <A HREF="https://addons.mozilla.org/en-US/firefox/addon/722">NoScript</a>, it won't.<br><br><A HREF="http://www.securityfocus.com/bid/31476/solution">Solution</a>:<br>Reports indicate that the vendor has address this issue in Firefox 3.1 pre-release nightly builds. A fixed version of Firefox 3.0.4 will be released in the near future.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21198278</guid>
<pubDate>Wed, 01 Oct 2008 12:39:15 EDT</pubDate>
</item>

<item>
<title>Firefox 3.0.3 remote null pointer DoS vulnerability</title>
<link>http://www.dslreports.com/forum/remark,21198202</link>
<description><![CDATA[<A HREF="/useremail/u/847301"><b>matunga</b></A> : &raquo;<A HREF="http://www.milw0rm.com/exploits/6614" >www.milw0rm.com/exploits/6614</A><br><br><b>Severity:</b> High<br><br><b>Description:</b><br>The mozilla firefox is vulnerable to user interface event dispatcher null<br>pointer dereference denial of service attacks. The dispatched event created<br>dynamically leads to firefox crash when it is called directly or in a<br>defined l<br>oop with number of generated  user interface events.The resultant crash<br>results in:<br><textarea name="code" class="text" cols=50 rows=10>Exception Type: EXC_BAD_ACCESS (SIGBUS)&#012;Exception Codes: KERN_PROTECTION_FAILURE at 0x0000000000000007&#012;Crashed Thread: 0&#012;Thread 0 Crashed: 0 libxpcom_core.dylib nsTArray_base::Length() const + 11&#012;(nsTArray.h:66)&#012;1 libgklayout.dylib&#012;nsContentUtils::GetAccelKeyCandidates(nsIDOMEvent*,&#012;nsTArray&amp;) + 261 (nsContentUtils.cpp:4083)&#012;</textarea><!--end code block--><br><b>a fully working exploit is available here (it will crash your firefox):</b><br>&raquo;<A HREF="http://www.secniche.org/moz303/index.html" >www.secniche.org/moz303/index.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21198202</guid>
<pubDate>Wed, 01 Oct 2008 12:28:03 EDT</pubDate>
</item>

</channel>
</rss>
