CVE Vulnerabilities

CVE-2002-1308

Published: Nov 29, 2002 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.

Affected Software

Name Vendor Start Version End Version
Mozilla Mozilla 0.9.6 (including) 0.9.6 (including)
Mozilla Mozilla 0.9.7 (including) 0.9.7 (including)
Mozilla Mozilla 0.9.8 (including) 0.9.8 (including)
Mozilla Mozilla 0.9.9 (including) 0.9.9 (including)
Mozilla Mozilla 1.0 (including) 1.0 (including)
Mozilla Mozilla 1.0.1 (including) 1.0.1 (including)
Mozilla Mozilla 1.1 (including) 1.1 (including)
Navigator Netscape 6.2 (including) 6.2 (including)
Navigator Netscape 6.2.1 (including) 6.2.1 (including)
Navigator Netscape 6.2.2 (including) 6.2.2 (including)
Navigator Netscape 6.2.3 (including) 6.2.3 (including)
Navigator Netscape 7.0 (including) 7.0 (including)

References