CVE-2002-1308 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Mozilla
5 documents5 sources
Severity
7.5HIGHNVD
EPSS
6.2%
top 9.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29
Latest updateApr 30
Description
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-hrvq-rhp3-7xpc: Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed↗2022-04-30
CVEList▶
CVE-2002-1308: Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed↗2004-09-01