Lucene search

K
cveRedhatCVE-2007-0777
HistoryFeb 26, 2007 - 7:28 p.m.

CVE-2007-0777

2007-02-2619:28:00
CWE-119
redhat
web.nvd.nist.gov
36
cve-2007-0777
javascript engine
mozilla firefox
denial of service
memory corruption
arbitrary code execution
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.967

Percentile

99.6%

The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption.

Affected configurations

Nvd
Node
mozillafirefoxRange1.51.5.0.10
OR
mozillafirefoxRange2.02.0.0.2
OR
mozillaseamonkeyRange<1.0.8
OR
mozillathunderbirdRange<1.5.0.10
Node
canonicalubuntu_linuxMatch5.10
OR
canonicalubuntu_linuxMatch6.06lts
OR
canonicalubuntu_linuxMatch6.10
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
mozillathunderbird*cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
canonicalubuntu_linux5.10cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
canonicalubuntu_linux6.06cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
canonicalubuntu_linux6.10cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.967

Percentile

99.6%