CVE-2007-1794
Mozilla < 1.7 - Remote Code Execution via Garbage Collection
Title source: llmDescription
The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used. NOTE: this issue might be related to CVE-2006-3805.
References (3)
Core 3
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102865-1
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/24624
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1178
Scores
EPSS
0.0434
EPSS Percentile
90.1%
Details
Status
published
Products (1)
mozilla/mozilla
< 1.7
Published
Apr 02, 2007
Tracked Since
Feb 18, 2026