The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | 3.6.2 | 3.6.2.x |
| mozilla / firefox | 3.6.3 | 3.6.3.x |
| mozilla / firefox | 3.6 | 3.6.x |