Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mozilla-embeddedUpgrade ru-linux-mozillafirebirdUpgrade de-linux-mozillafirebirdUpgrade mozilla-firebirdUpgrade de-linux-netscapeUpgrade mozilla-gtkUpgrade linux-mozillaUpgrade mozilla-gtk1Upgrade ja-mozillafirebird-gtk2Upgrade netscape7Upgrade pt_BR-netscape7Upgrade mozilla-gtk2Upgrade linux-firefoxUpgrade zhTW-linux-mozillafirebirdUpgrade zhCN-linux-mozillafirebirdUpgrade firefoxUpgrade mozilla-thunderbirdUpgrade linux-netscapeUpgrade ja-netscape7Upgrade el-linux-mozillafirebirdUpgrade linux-mozillafirebirdUpgrade ja-linux-mozillafirebird-gtk1Upgrade phoenixUpgrade mozillaUpgrade de-netscape7Upgrade ja-linux-netscapeUpgrade mozilla+ipv6Upgrade linux-phoenixUpgrade fr-linux-netscapeUpgrade linux-mozilla-develUpgrade fr-netscape7 | Dec 10, 2025 | Sep 10, 2005 |
| Gentoo Linux | — | Upgrade net-libs/gecko-sdk.Upgrade www-client/mozilla-bin.Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Sep 9, 2005 |
| Hpux | — | Apply the remediation from HP for CVE-2005-2871 | Aug 11, 2017 | Sep 9, 2005 |
| Mfsa2005 57 | — | Upgrade to Mozilla Firefox version 1.7.12 | Sep 29, 2005 | Sep 9, 2005 |
| Ubuntu | — | Upgrade mozilla-thunderbird | Nov 8, 2024 | Sep 9, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub