9.8

CVE-2003-0791

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

Data is provided by the National Vulnerability Database (NVD)
MozillaMozilla Version <= 1.4
ScoOpenserver Version5.0.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.15% 0.765
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

http://www.osvdb.org/8390
Patch
Vendor Advisory
Broken Link
http://www.securityfocus.com/advisories/6979
Patch
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
http://www.securityfocus.com/bid/9322
Patch
Third Party Advisory
Vendor Advisory
Broken Link
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=221526
Patch
Vendor Advisory
Issue Tracking