Lucene search

K
freebsdFreeBSDA4FD8F53-05EB-11D9-B45D-000C41E2CDAD
HistoryAug 02, 2004 - 12:00 a.m.

mozilla -- SOAPParameter integer overflow

2004-08-0200:00:00
vuxml.freebsd.org
24

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.837 High

EPSS

Percentile

98.5%

zen-parse discovered and iDEFENSE reported an exploitable
integer overflow in a scriptable Mozilla component
`SOAPParameter’:

Improper input validation to the SOAPParameter object
constructor in Netscape and Mozilla allows execution of
arbitrary code. The SOAPParameter object’s constructor
contains an integer overflow which allows controllable
heap corruption. A web page can be constructed to
leverage this into remote execution of arbitrary code.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.837 High

EPSS

Percentile

98.5%