CVE-2003-0791

CRITICAL

Mozilla < 1.4 - Remote Code Execution via Script.prototype.thaw Deserialization

Title source: llm
STIX 2.1

Description

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

References (6)

Core 6
Core References
Broken Link vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2004:021
Broken Link, Patch, Vendor Advisory vdb-entry x_refsource_osvdb
http://www.osvdb.org/8390
URL Repurposed third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11103/
Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9322
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=221526
Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory vendor-advisory x_refsource_sco
http://www.securityfocus.com/advisories/6979

Scores

CVSS v3 9.8
EPSS 0.0213
EPSS Percentile 79.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
mozilla/mozilla < 1.4
sco/openserver 5.0.7
Published Oct 07, 2003
Tracked Since Feb 18, 2026