Mozilla Firefox Unspecified Javascript Remote Code Execution Vulnerability
BID:20282
Info
Mozilla Firefox Unspecified Javascript Remote Code Execution Vulnerability
| Bugtraq ID: | 20282 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2006 12:00AM |
| Updated: | Oct 02 2006 06:05PM |
| Credit: | Mischa Spiegelmock and Andrew Wbeelsoi are credited with discovering this vulnerability. |
| Vulnerable: |
Mozilla Firefox 1.5 beta 2 Mozilla Firefox 1.5 beta 1 Mozilla Firefox 1.5 .8 Mozilla Firefox 1.5 .6 Mozilla Firefox 1.5 Mozilla Firefox 1.0.8 Mozilla Firefox 1.0.7 Mozilla Firefox 1.0.6 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.5 Mozilla Firefox 1.0.4 Mozilla Firefox 1.0.3 Mozilla Firefox 1.0.2 Mozilla Firefox 1.0.1 Mozilla Firefox 1.0 Mozilla Firefox 0.10.1 Mozilla Firefox 0.10 Mozilla Firefox 0.9.3 Mozilla Firefox 0.9.2 Mozilla Firefox 0.9.1 Mozilla Firefox 0.9 rc Mozilla Firefox 0.9 Mozilla Firefox 0.8 Mozilla Firefox Preview Release Mozilla Firefox 2.0 beta 1 Mozilla Firefox 1.5.0.7 Mozilla Firefox 1.5.0.6 Mozilla Firefox 1.5.0.5 Mozilla Firefox 1.5.0.4 Mozilla Firefox 1.5.0.3 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.2 Mozilla Firefox 1.5.0.1 |
| Not Vulnerable: | |
Discussion
Mozilla Firefox Unspecified Javascript Remote Code Execution Vulnerability
Mozilla Firefox is prone to a remote code-execution vulnerability because the application fails to properly sanitize user-supplied input before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or execute arbitrary machine code in the context of the affected application.
Details regarding this vulnerability are not currently available; this BID will be updated when more information becomes available.
Mozilla Firefox is prone to a remote code-execution vulnerability because the application fails to properly sanitize user-supplied input before using it to create new JavaScript objects.
Successful exploits may allow an attacker to crash the application or execute arbitrary machine code in the context of the affected application.
Details regarding this vulnerability are not currently available; this BID will be updated when more information becomes available.
Exploit / POC
Mozilla Firefox Unspecified Javascript Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Mozilla Firefox Unspecified Javascript Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Mozilla Firefox Unspecified Javascript Remote Code Execution Vulnerability
References:
References:
- Hackers claim zero-day flaw in Firefox (Joris Evers)