Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
Mozilla · Firefox and Thunderbird
Date added (CISA)
2022-03-28
Remediation due
2022-04-18
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.