← Back

CVE-2003-0791

nvd nist
Published: Oct 7, 2003Modified: Apr 16, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

Affected (2)

Products: Mozilla: Mozilla · Sco: Openserver
1 product
Mozilla
1 product
Openserver
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0.7

References (12)

Source: cve@mitre.org
URL Repurposed
Source: cve@mitre.org
Broken LinkPatchVendor Advisory
Source: cve@mitre.org
Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
Source: cve@mitre.org
Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
URL Repurposed
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.