CVE-2002-1091

Netscape <6.2.3 & Mozilla <1.0.1 - RCE

Title source: llm
STIX 2.1

Description

Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2003-046.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5665
Various Sources vendor-advisory x_refsource_mandrake
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2002:075
Patch, Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-192.html
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=157989
Various Sources x_refsource_misc
http://crash.ihug.co.nz/~Sneuro/zerogif/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103134051120770&w=2
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10058.php

Scores

EPSS 0.0428
EPSS Percentile 90.0%

Details

Status published
Products (13)
mozilla/mozilla 0.9.5
mozilla/mozilla 0.9.6
mozilla/mozilla 0.9.7
mozilla/mozilla 0.9.8
mozilla/mozilla 0.9.9
mozilla/mozilla 1.0
netscape/navigator 6.2
netscape/navigator 6.2.1
netscape/navigator 6.2.2
netscape/navigator 6.2.3
... and 3 more
Published Oct 04, 2002
Tracked Since Feb 18, 2026