CVE-2003-0791
Summary
| CVE | CVE-2003-0791 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-10-07 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Problem Types: CWE-502 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Mozilla | All | All | All | All |
| Operating System | Sco | Openserver | 5.0.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Browser Script.prototype.freeze/thaw Arbitrary Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
| Mandriva Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| Secunia - Advisories - Mandrake update for Mozilla | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | URL Repurposed |
| Malformed Request | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory |
| 221526 – JS Script.thaw is a security hole | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking, Patch, Vendor Advisory |
| www.osvdb.org/8390 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.