Critical severity9.8NVD Advisory· Published Oct 7, 2003· Updated Apr 16, 2026
CVE-2003-0791
CVE-2003-0791
Description
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
Affected products
2- cpe:2.3:o:sco:openserver:5.0.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.osvdb.org/8390nvdBroken LinkPatchVendor Advisory
- www.securityfocus.com/advisories/6979nvdBroken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- www.securityfocus.com/bid/9322nvdBroken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPatchVendor Advisory
- secunia.com/advisories/11103/nvdURL Repurposed
- www.mandriva.com/security/advisoriesnvdBroken Link
News mentions
0No linked articles in our index yet.