Fri Apr 18 2025 16:19:22 PDT
  • Bug ID: 407720, 390597, 373344, 398085, 406572, 391028, 406036, 402087

ID Type Summary Product Comp Assignee Status Resolution Updated
402087 Setting GC-Zeal before JS_CompileScript() causes null-deref (obj->map == 0x0) in JSOP_DEFFUN Core JavaScript Engine igor RESO FIXE 2008-03-22
391028 drawImage with broken PNG draws random memory Core Graphics: Canvas2D vladimir RESO FIXE 2008-03-20
406572 JSOP_CLOSURE unconditionally replaces properties of the variable object Core JavaScript Engine igor VERI FIXE 2012-10-16
373344 Mousedown event listener changing body style and alert()ing crashes [@ PresShell::HandleEventInternal] browser Core DOM: UI Events & Foc smaug VERI FIXE 2019-03-13
406036 putImageData draws random memory Core Graphics: Canvas2D vladimir VERI FIXE 2008-02-07
398085 Crash with large switch statement [@ js_Interpret] Core JavaScript Engine igor VERI FIXE 2012-01-23
407720 js_FindClassObject causes crashes with getter/setter Core JavaScript Engine igor VERI FIXE 2008-03-25
390597 watch point + eval-as-setter allows access to dead JSStackFrame Core JavaScript Engine mrbkap VERI FIXE 2008-03-29
8 bugs found.

File a new bug in the "Core" product