5
CVSSv2

CVE-2000-0655

Published: 25/07/2000 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Netscape Communicator 4.73 and previous versions allows remote malicious users to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla mozilla m15

netscape communicator 4.05

netscape communicator 4.6

netscape communicator 4.7

netscape communicator 4.72

netscape communicator 4.73

netscape communicator 4.07

netscape communicator 4.08

netscape communicator 4.5

netscape communicator 4.5_beta

netscape communicator 4.0

netscape communicator 4.06

netscape communicator 4.51

netscape communicator 4.61

Exploits

source: wwwsecurityfocuscom/bid/1503/info Netscape Browsers use the Independent JPEG Group's decoder library to process JPEG encoded images The library functions skip JPEG comments; however, the browser uses a custom function to process these comments and store them in memory The comment includes a 2-byte "length" field which indicates ...