VYPR
Unrated severityNVD Advisory· Published Dec 9, 2005· Updated Apr 16, 2026

CVE-2005-4134

CVE-2005-4134

Description

Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox. Also, it has been independently reported that Netscape 8.1 does not have this issue.

Affected products

11
  • cpe:2.3:a:k-meleon_project:k-meleon:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:k-meleon_project:k-meleon:*:*:*:*:*:*:*:*range: <=0.9
    • cpe:2.3:a:k-meleon_project:k-meleon:0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:k-meleon_project:k-meleon:0.7_service_pack_1:*:*:*:*:*:*:*
    • cpe:2.3:a:k-meleon_project:k-meleon:0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:k-meleon_project:k-meleon:0.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:k-meleon_project:k-meleon:0.8.2:*:*:*:*:*:*:*
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
    Range: <=1.5
  • cpe:2.3:a:mozilla:mozilla_suite:*:*:*:*:*:*:*:*
    Range: <=1.7.12
  • cpe:2.3:a:netscape:navigator:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:netscape:navigator:*:*:*:*:*:*:*:*range: <=8.0.40
    • cpe:2.3:a:netscape:navigator:7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:netscape:navigator:7.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

54

News mentions

0

No linked articles in our index yet.