The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 33.0.x |
| mozilla / seamonkey | - | 2.30.x |
| mozilla / thunderbird | - | 31.2.x |
| mozilla / firefox | - | 31.2.x |