CVE-2002-1091

5 documents5 sources
Severity
7.5HIGH
EPSS
6.5%
top 8.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 4
Latest updateApr 30

Description

Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDmozilla/mozilla6 versions+5
NVDnetscape/navigator4 versions+3
NVDopera_software/opera_web_browser5.12, 6.0, 6.0.1+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c7hg-5qw2-jh2v: Netscape 62022-04-30
CVEList
CVE-2002-1091: Netscape 62004-09-01

📋Vendor Advisories

1
Red Hat
security flaw2002-09-06

💬Community

1
Bugzilla
CVE-2002-1091 security flaw2018-08-16
CVE-2002-1091 (HIGH CVSS 7.5) | Netscape 6.2.3 and earlier | cvebase.io