CVE-2005-0989: Medium severity Mozilla Firefox vulnerability
Published Apr 6, 2005
·Updated
The findreplen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
Affected Software
4 affected components
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Mozilla Mozilla=1.7.6
Netscape Navigator=7.2
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 6, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0989?
CVE-2005-0989 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2005-0989?
To mitigate CVE-2005-0989, users should upgrade to the latest versions of affected software.
3
What versions are affected by CVE-2005-0989?
CVE-2005-0989 affects Mozilla Suite 1.7.6, Firefox 1.0.1, 1.0.2, and Netscape 7.2.
4
What type of attack can exploit CVE-2005-0989?
CVE-2005-0989 can be exploited by remote attackers to read portions of heap memory.
5
Are there any known exploits for CVE-2005-0989?
Yes, there are reports of exploitation for CVE-2005-0989, allowing attackers to access sensitive memory data.