Vulnerability record · CVE-2003-0791 · published 7 October 2003
CVE-2003-0791: Mozilla deserialization of untrusted data vulnerability
Mozilla · Mozilla
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
Description
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://secunia.com/advisories/11103/ | URL Repurposed |
| http://www.mandriva.com/security/advisories?name=MDKSA-2004:021 | Broken Link |
| http://www.osvdb.org/8390 | Broken LinkPatchVendor Advisory |
| http://www.securityfocus.com/advisories/6979 | Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory |
| http://www.securityfocus.com/bid/9322 | Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory |
| https://bugzilla.mozilla.org/show_bug.cgi?id=221526 | Issue TrackingPatchVendor Advisory |
| http://secunia.com/advisories/11103/ | URL Repurposed |
| http://www.mandriva.com/security/advisories?name=MDKSA-2004:021 | Broken Link |
| http://www.osvdb.org/8390 | Broken LinkPatchVendor Advisory |
| http://www.securityfocus.com/advisories/6979 | Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory |
| http://www.securityfocus.com/bid/9322 | Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory |
| https://bugzilla.mozilla.org/show_bug.cgi?id=221526 | Issue TrackingPatchVendor Advisory |
Track CVE-2003-0791 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0791), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.