← Vulnerability feed

Vulnerability record · CVE-2003-0791 · published 7 October 2003

CVE-2003-0791: Mozilla deserialization of untrusted data vulnerability

Mozilla · Mozilla

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

9.8 CVSS 3.1 Critical EPSS 2.1% · top 18.8% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/11103/ URL Repurposed
http://www.mandriva.com/security/advisories?name=MDKSA-2004:021 Broken Link
http://www.osvdb.org/8390 Broken LinkPatchVendor Advisory
http://www.securityfocus.com/advisories/6979 Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.securityfocus.com/bid/9322 Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=221526 Issue TrackingPatchVendor Advisory
http://secunia.com/advisories/11103/ URL Repurposed
http://www.mandriva.com/security/advisories?name=MDKSA-2004:021 Broken Link
http://www.osvdb.org/8390 Broken LinkPatchVendor Advisory
http://www.securityfocus.com/advisories/6979 Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
http://www.securityfocus.com/bid/9322 Broken LinkPatchThird Party AdvisoryVDB EntryVendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=221526 Issue TrackingPatchVendor Advisory

Track CVE-2003-0791 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-1794Mozilla vulnerabilityThe Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors invol…EPSS 4.3%10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0902Mozilla vulnerabilityMultiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote att…EPSS 10%10.0CVE-2004-0903Mozilla vulnerabilityStack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Th…EPSS 9.7%10.0CVE-2004-0904Mozilla firefox vulnerabilityInteger overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r…EPSS 8.0%10.0CVE-2004-0722Mozilla vulnerabilityInteger overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allo…EPSS 13%10.0CVE-2004-0757Mozilla firefox vulnerabilityHeap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow r…EPSS 5.3%10.0CVE-2004-0764Mozilla firefox vulnerabilityMozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2003-0791), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.