CVE-2007-1794

Mozilla < 1.7 - Remote Code Execution via Garbage Collection

Title source: llm
STIX 2.1

Description

The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used. NOTE: this issue might be related to CVE-2006-3805.

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102865-1
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24624
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1178

Scores

EPSS 0.0434
EPSS Percentile 90.1%

Details

Status published
Products (1)
mozilla/mozilla < 1.7
Published Apr 02, 2007
Tracked Since Feb 18, 2026