The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://secunia.com/advisories/14938
http://secunia.com/advisories/14992
http://secunia.com/advisories/19823
http://securitytracker.com/id?1013742
http://securitytracker.com/id?1013743
http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml
http://www.mozilla.org/security/announce/mfsa2005-40.html
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.redhat.com/support/errata/RHSA-2005-383.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.redhat.com/support/errata/RHSA-2005-386.html
http://www.redhat.com/support/errata/RHSA-2005-601.html
http://www.securityfocus.com/bid/13232
http://www.securityfocus.com/bid/15495
https://bugzilla.mozilla.org/show_bug.cgi?id=290162
https://exchange.xforce.ibmcloud.com/vulnerabilities/20123
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100018
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10629
Source: MITRE
Published: 2005-05-02
Updated: 2017-10-11
Type: NVD-CWE-Other
Base Score: 7.5
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 10
Severity: HIGH
OR
cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
21952 | CentOS 4 : thunderbird (CESA-2005:601) | Nessus | CentOS Local Security Checks | high |
21931 | CentOS 4 : mozilla (CESA-2005:386) | Nessus | CentOS Local Security Checks | high |
21930 | CentOS 3 : mozilla (CESA-2005:384) | Nessus | CentOS Local Security Checks | high |
21929 | CentOS 4 : Firefox (CESA-2005:383) | Nessus | CentOS Local Security Checks | high |
20560 | Ubuntu 4.10 / 5.04 : mozilla-thunderbird vulnerabilities (USN-157-1) | Nessus | Ubuntu Local Security Checks | high |
20546 | Ubuntu 4.10 : mozilla-firefox vulnerabilities (USN-149-3) | Nessus | Ubuntu Local Security Checks | high |
20513 | Ubuntu 5.04 : mozilla-firefox, mozilla vulnerabilities (USN-124-1) | Nessus | Ubuntu Local Security Checks | high |
3239 | Mozilla Firefox < 1.0.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3238 | Mozilla Firefox < 1.7.12 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
19478 | Debian DSA-781-1 : mozilla-thunderbird - several vulnerabilities | Nessus | Debian Local Security Checks | high |
19277 | RHEL 4 : thunderbird (RHSA-2005:601) | Nessus | Red Hat Local Security Checks | high |
19269 | Mozilla Thunderbird < 1.0.6 Multiple Vulnerabilities | Nessus | Windows | high |
3099 | Mozilla Firefox < 1.0.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3067 | Mozilla Firefox < 1.7.10 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3066 | Mozilla Firefox < 1.0.5 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
18277 | Mandrake Linux Security Advisory : mozilla (MDKSA-2005:088) | Nessus | Mandriva Local Security Checks | high |
2902 | Mozilla Firefox < 1.7.8 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2887 | Mozilla Firefox < 1.0.4 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
18162 | RHEL 2.1 / 3 : Mozilla (RHSA-2005:384) | Nessus | Red Hat Local Security Checks | high |
18154 | SUSE-SA:2005:028: Mozilla. Mozilla Firefox | Nessus | SuSE Local Security Checks | high |
18148 | RHEL 4 : Mozilla (RHSA-2005:386) | Nessus | Red Hat Local Security Checks | high |
18109 | RHEL 4 : firefox (RHSA-2005:383) | Nessus | Red Hat Local Security Checks | high |
18090 | GLSA-200504-18 : Mozilla Firefox, Mozilla Suite: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
18065 | Mozilla Browser < 1.7.7 Multiple Vulnerabilities | Nessus | Windows | high |
18064 | Firefox < 1.0.3 Multiple Vulnerabilities | Nessus | Windows | high |
2789 | Mozilla Firefox < 1.7.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2788 | Mozilla Firefox < 1.0.3 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2703 | Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities (deprecated) | Nessus Network Monitor | SMTP Clients | medium |
2671 | Mozilla Firefox < 1.7.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2652 | Mozilla Firefox < 1.0.1 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2603 | MSN Messenger < 6.2.0205 PNG File Remote Overflow (deprecated) | Nessus Network Monitor | Internet Messengers | medium |
2602 | Microsoft Media Player Version 9 PNG Multiple Vulnerabilities (deprecated) | Nessus Network Monitor | Generic | medium |
1775 | Mozilla Firefox XML User Interface Language Browser Interface Spoofing (deprecated) | Nessus Network Monitor | Web Clients | medium |
1773 | Mozilla Firefox < 1.7.1 / Thunderbird < 0.7.1 POP3 Remote Heap Overflow (deprecated) | Nessus Network Monitor | Web Clients | medium |
1772 | Mozilla Firefox < 1.7.1 Cross-Domain Frame Loading Vulnerability (deprecated) | Nessus Network Monitor | Web Clients | medium |
1771 | Mozilla Firefox < 1.7.2 Non-FQDN SSL Certificate Spoofing | Nessus Network Monitor | Web Clients | medium |
1770 | Mozilla Firefox < 1.7.1 SSL Redirect Spoofing | Nessus Network Monitor | Web Clients | medium |
2116 | Mozilla Firefox Input Type HTML Tag Unauthorized Access (deprecated) | Nessus Network Monitor | Web Clients | medium |
801373 | Mozilla XML User Interface Language Browser Interface Spoofing | Log Correlation Engine | Web Clients | medium |
801318 | Mozilla Browser < 1.7.8 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801295 | Mozilla Firefox < 1.0.4 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801294 | Mozilla Browser < 1.7.12 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801293 | Mozilla < 1.7.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801292 | Mozilla Browser < 1.7.2 Non-FQDN SSL Certificate Spoofing | Log Correlation Engine | Web Clients | medium |
801263 | Mozilla < 1.7.1 SSL Redirect Spoofing | Log Correlation Engine | Web Clients | medium |
801257 | Mozilla Browser < 1.7.10 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801229 | Mozilla Browser Input Type HTML Tag Unauthorized Access | Log Correlation Engine | Web Clients | medium |
801228 | Mozilla < 1.7.1 Cross-Domain Frame Loading Vulnerability | Log Correlation Engine | Web Clients | medium |
801221 | Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities | Log Correlation Engine | SMTP Clients | high |
801217 | Mozilla Firefox < 1.0.5 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801215 | Mozilla < 1.7.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801211 | Mozilla Browser <1.7.1 / Thunderbird < 0.7.1 SendUIDL POP3 Message Handling Remote Heap Overflow | Log Correlation Engine | Web Clients | medium |
800781 | Firefox < 1.0.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800777 | Firefox < 1.0.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800745 | Firefox < 1.0.3 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |