Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0989Mozilla Firefox vulnerability

10 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
25.3%
top 3.79%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 2
Latest updateMay 3

Description

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox1.0.1, 1.0.2+1
NVDmozilla/mozilla1.7.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fm33-hrc3-jr7v: The find_replen function in jsstr2022-05-03
CVEList
CVE-2005-0989: The find_replen function in jsstr2005-04-06

💥Exploits & PoCs

1
Exploit-DB
Mozilla Suite/Firefox - JavaScript Lambda Replace Heap Memory Disclosure2005-04-04

📋Vendor Advisories

3
Ubuntu
Mozilla Thunderbird vulnerabilities2005-08-01
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities2005-07-28
Red Hat
security flaw2005-04-15

💬Community

2
Bugzilla
CVE-2005-0989 security flaw2018-08-16
Bugzilla
CAN-2005-0752 Multiple firefox issues. (CAN-2005-0989)2005-04-16
CVE-2005-0989 — Mozilla Firefox vulnerability | cvebase