CVE-2002-2061

Mozilla < 1.0 - Remote Code Execution via Malformed PNG Image

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2002:074

Scores

EPSS 0.0349
EPSS Percentile 87.9%

Details

Status published
Products (2)
mozilla/mozilla < 1.0
netscape/navigator 6.2.3
Published Dec 31, 2002
Tracked Since Feb 18, 2026