Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://secunia.com/advisories/14938
http://secunia.com/advisories/14992
http://secunia.com/advisories/14996
http://www.mikx.de/firesearching/
http://www.mozilla.org/security/announce/mfsa2005-38.html
http://www.redhat.com/support/errata/RHSA-2005-383.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.redhat.com/support/errata/RHSA-2005-386.html
http://www.securityfocus.com/bid/13211
http://www.securityfocus.com/bid/15495
https://bugzilla.mozilla.org/show_bug.cgi?id=290037
https://exchange.xforce.ibmcloud.com/vulnerabilities/20125
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9961
Source: MITRE
Published: 2005-05-02
Updated: 2017-10-11
Type: NVD-CWE-Other
Base Score: 7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 10
Severity: HIGH
OR
cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.5:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
21931 | CentOS 4 : mozilla (CESA-2005:386) | Nessus | CentOS Local Security Checks | high |
21930 | CentOS 3 : mozilla (CESA-2005:384) | Nessus | CentOS Local Security Checks | high |
21929 | CentOS 4 : Firefox (CESA-2005:383) | Nessus | CentOS Local Security Checks | high |
20546 | Ubuntu 4.10 : mozilla-firefox vulnerabilities (USN-149-3) | Nessus | Ubuntu Local Security Checks | high |
20513 | Ubuntu 5.04 : mozilla-firefox, mozilla vulnerabilities (USN-124-1) | Nessus | Ubuntu Local Security Checks | high |
3239 | Mozilla Firefox < 1.0.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3238 | Mozilla Firefox < 1.7.12 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3099 | Mozilla Firefox < 1.0.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3067 | Mozilla Firefox < 1.7.10 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3066 | Mozilla Firefox < 1.0.5 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
18277 | Mandrake Linux Security Advisory : mozilla (MDKSA-2005:088) | Nessus | Mandriva Local Security Checks | high |
2902 | Mozilla Firefox < 1.7.8 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2887 | Mozilla Firefox < 1.0.4 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
18162 | RHEL 2.1 / 3 : Mozilla (RHSA-2005:384) | Nessus | Red Hat Local Security Checks | high |
18154 | SUSE-SA:2005:028: Mozilla. Mozilla Firefox | Nessus | SuSE Local Security Checks | high |
18148 | RHEL 4 : Mozilla (RHSA-2005:386) | Nessus | Red Hat Local Security Checks | high |
18109 | RHEL 4 : firefox (RHSA-2005:383) | Nessus | Red Hat Local Security Checks | high |
18065 | Mozilla Browser < 1.7.7 Multiple Vulnerabilities | Nessus | Windows | high |
18064 | Firefox < 1.0.3 Multiple Vulnerabilities | Nessus | Windows | high |
2789 | Mozilla Firefox < 1.7.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2788 | Mozilla Firefox < 1.0.3 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2703 | Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities (deprecated) | Nessus Network Monitor | SMTP Clients | medium |
2671 | Mozilla Firefox < 1.7.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2652 | Mozilla Firefox < 1.0.1 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2603 | MSN Messenger < 6.2.0205 PNG File Remote Overflow (deprecated) | Nessus Network Monitor | Internet Messengers | medium |
2602 | Microsoft Media Player Version 9 PNG Multiple Vulnerabilities (deprecated) | Nessus Network Monitor | Generic | medium |
1775 | Mozilla Firefox XML User Interface Language Browser Interface Spoofing (deprecated) | Nessus Network Monitor | Web Clients | medium |
1773 | Mozilla Firefox < 1.7.1 / Thunderbird < 0.7.1 POP3 Remote Heap Overflow (deprecated) | Nessus Network Monitor | Web Clients | medium |
1772 | Mozilla Firefox < 1.7.1 Cross-Domain Frame Loading Vulnerability (deprecated) | Nessus Network Monitor | Web Clients | medium |
1771 | Mozilla Firefox < 1.7.2 Non-FQDN SSL Certificate Spoofing | Nessus Network Monitor | Web Clients | medium |
1770 | Mozilla Firefox < 1.7.1 SSL Redirect Spoofing | Nessus Network Monitor | Web Clients | medium |
2116 | Mozilla Firefox Input Type HTML Tag Unauthorized Access (deprecated) | Nessus Network Monitor | Web Clients | medium |
801373 | Mozilla XML User Interface Language Browser Interface Spoofing | Log Correlation Engine | Web Clients | medium |
801318 | Mozilla Browser < 1.7.8 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801295 | Mozilla Firefox < 1.0.4 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801294 | Mozilla Browser < 1.7.12 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801293 | Mozilla < 1.7.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801292 | Mozilla Browser < 1.7.2 Non-FQDN SSL Certificate Spoofing | Log Correlation Engine | Web Clients | medium |
801263 | Mozilla < 1.7.1 SSL Redirect Spoofing | Log Correlation Engine | Web Clients | medium |
801257 | Mozilla Browser < 1.7.10 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801229 | Mozilla Browser Input Type HTML Tag Unauthorized Access | Log Correlation Engine | Web Clients | medium |
801228 | Mozilla < 1.7.1 Cross-Domain Frame Loading Vulnerability | Log Correlation Engine | Web Clients | medium |
801221 | Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities | Log Correlation Engine | SMTP Clients | high |
801217 | Mozilla Firefox < 1.0.5 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801215 | Mozilla < 1.7.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801211 | Mozilla Browser <1.7.1 / Thunderbird < 0.7.1 SendUIDL POP3 Message Handling Remote Heap Overflow | Log Correlation Engine | Web Clients | medium |
800781 | Firefox < 1.0.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800777 | Firefox < 1.0.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800745 | Firefox < 1.0.3 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |