vendor:
Firefox
by:
Aviv Raff
7.5
CVSS
HIGH
Remote Code Execution
Unknown
CWE
Product Name: Firefox
Affected Version From: Mozilla Firefox version 1.04 and below
Affected Version To: Mozilla Firefox version 1.04 and below
Patch Exists: NO
Related CWE: None mentioned
CPE: a:mozilla:firefox
Platforms Tested: None mentioned
2005-2006
Mozilla (Firefox<=v1.04) InstallVersion->compareTo Remote Code Execution Exploit
This exploit allows remote code execution in Mozilla Firefox version 1.04 and below. It takes advantage of a vulnerability in the InstallVersion->compareTo function.
Mitigation:
Upgrade to a newer version of Mozilla Firefox to mitigate this vulnerability.