CVE-2002-1091: High severity Mozilla Mozilla vulnerability
Published Oct 4, 2002
·Updated
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.
Affected Software
13 affected components
Mozilla Mozilla=0.9.5
Mozilla Mozilla=0.9.6
Mozilla Mozilla=0.9.7
Mozilla Mozilla=0.9.8
Mozilla Mozilla=0.9.9
Mozilla Mozilla=1.0
Netscape Navigator=6.2
Netscape Navigator=6.2.1
Netscape Navigator=6.2.2
Netscape Navigator=6.2.3
Opera Software Opera Web Browser=5.12
Opera Software Opera Web Browser=6.0
Opera Software Opera Web Browser=6.0.1
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1091?
CVE-2002-1091 has a high severity due to the potential for remote attackers to execute arbitrary code.
2
How do I fix CVE-2002-1091?
To fix CVE-2002-1091, update to the latest version of Netscape or Mozilla that does not contain this vulnerability.
3
Which software versions are affected by CVE-2002-1091?
Affected software includes Netscape Navigator versions 6.2.3 and earlier, and Mozilla versions 1.0.1 and earlier.
4
Can CVE-2002-1091 be exploited remotely?
Yes, CVE-2002-1091 can be exploited remotely through a specially crafted GIF image.
5
What type of vulnerability is CVE-2002-1091?
CVE-2002-1091 is a heap memory corruption vulnerability.