header-logo
Suggest Exploit
vendor:
Mozilla
by:
Unknown
7.5
CVSS
HIGH
Heap Overflow
120
CWE
Product Name: Mozilla
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:mozilla:mozilla
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

Remote Heap Overflow in Mozilla

Mozilla is prone to a remotely exploitable heap overflow that is exposed when the browser handles non-ASCII characters in URIs. This issue could be exploited by enticing a user to open a hyperlink that references a malicious URI. Successful exploitation will allow execution of arbitrary code in the context of the client user.

Mitigation:

Unknown
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/11169/info

Mozilla is prone to a remotely exploitable heap overflow that is exposed when the browser handles non-ASCII characters in URIs. 

This issue could be exploited by enticing a user to open a hyperlink that references a malicious URI. Successful exploitation will allow execution of arbitrary code in the context of the client user.

http://é------------------------------------------------aaaabbbb-----/

http://é------------------------------------------------þßý-----/

http://é------------------------------------------------aaaa$ðý-----/