CVE-2004-0722

Mozilla < 1.6 and Netscape Navigator 7.0-7.1 - Remote Code Execution via SOAPParameter Integer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2004-0722. PoCs published by zen-parse.

AI-analyzed exploit summary This exploit leverages an integer overflow in the SOAPParameter object constructor in Mozilla and Netscape browsers. By creating an excessively large array and passing it to the SOAPParameter constructor, it corrupts heap memory, potentially leading to remote code execution.

Description

Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by zen-parse · textdoslinux
https://www.exploit-db.com/exploits/24346

This exploit leverages an integer overflow in the SOAPParameter object constructor in Mozilla and Netscape browsers. By creating an excessively large array and passing it to the SOAPParameter constructor, it corrupts heap memory, potentially leading to remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Mozilla prior to 1.7.1, Netscape 7.0, 7.1
No auth needed
Prerequisites: Victim must visit a malicious web page using a vulnerable browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Various Sources vendor-advisory x_refsource_sco
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2004-421.html
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=236618
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9378
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15495
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16862
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4629

Scores

EPSS 0.1325
EPSS Percentile 95.9%

Details

Status published
Products (3)
mozilla/mozilla 1.6
netscape/navigator 7.0
netscape/navigator 7.1
Published Aug 18, 2004
Tracked Since Feb 18, 2026