CVE-2009-1169
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.
Date published : 2009-03-26
http://www.securityfocus.com/bid/34235
http://support.avaya.com/elmodocs2/security/ASA-2009-113.htm