Mozilla Javascript Array Object Heap Overflow (deprecated)

High Nessus Network Monitor Plugin ID 1328


The remote host is vulnerable to a heap overflow.


The remote host is running a version of the Mozilla browser that contains a vulnerability in the JavaScript implementation. The condition is triggered when a large integer value (x40000000) is passed to the array constructor. The implementation of the array class fails to check for oversized integers, causing memory in the heap to be corrupted.


Upgrade to Mozilla 1.0.1, 1.1 or disable Javascript.

Plugin Details

Severity: High

ID: 1328

Family: SMTP Clients

Published: 2004/08/20

Updated: 2019/03/06

Dependencies: 1330

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 7.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:U/RC:C

CVSS v3.0

Base Score: 8.1

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:U/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:mozilla

Reference Information

BID: 5742