The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://secunia.com/advisories/14938
http://secunia.com/advisories/14992
http://secunia.com/advisories/19823
http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml
http://www.mozilla.org/security/announce/mfsa2005-41.html
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.redhat.com/support/errata/RHSA-2005-383.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.redhat.com/support/errata/RHSA-2005-386.html
http://www.redhat.com/support/errata/RHSA-2005-601.html
http://www.securityfocus.com/bid/13233
http://www.securityfocus.com/bid/15495
https://bugzilla.mozilla.org/show_bug.cgi?id=289074
https://bugzilla.mozilla.org/show_bug.cgi?id=289083
https://bugzilla.mozilla.org/show_bug.cgi?id=289961
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100017
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11291
Source: MITRE
Published: 2005-05-02
Updated: 2017-10-11
Type: NVD-CWE-Other
Base Score: 5.1
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 4.9
Severity: MEDIUM
OR
cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.3:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:alpha:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:beta:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc1:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc2:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
21952 | CentOS 4 : thunderbird (CESA-2005:601) | Nessus | CentOS Local Security Checks | high |
21931 | CentOS 4 : mozilla (CESA-2005:386) | Nessus | CentOS Local Security Checks | high |
21930 | CentOS 3 : mozilla (CESA-2005:384) | Nessus | CentOS Local Security Checks | high |
21929 | CentOS 4 : Firefox (CESA-2005:383) | Nessus | CentOS Local Security Checks | high |
20560 | Ubuntu 4.10 / 5.04 : mozilla-thunderbird vulnerabilities (USN-157-1) | Nessus | Ubuntu Local Security Checks | high |
20556 | Ubuntu 4.10 / 5.04 : mozilla vulnerabilities (USN-155-1) | Nessus | Ubuntu Local Security Checks | high |
20546 | Ubuntu 4.10 : mozilla-firefox vulnerabilities (USN-149-3) | Nessus | Ubuntu Local Security Checks | high |
20525 | Ubuntu 5.04 : mozilla-firefox vulnerabilities (USN-134-1) | Nessus | Ubuntu Local Security Checks | high |
20513 | Ubuntu 5.04 : mozilla-firefox, mozilla vulnerabilities (USN-124-1) | Nessus | Ubuntu Local Security Checks | high |
3239 | Mozilla Firefox < 1.0.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3238 | Mozilla Firefox < 1.7.12 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
19478 | Debian DSA-781-1 : mozilla-thunderbird - several vulnerabilities | Nessus | Debian Local Security Checks | high |
19277 | RHEL 4 : thunderbird (RHSA-2005:601) | Nessus | Red Hat Local Security Checks | high |
19269 | Mozilla Thunderbird < 1.0.6 Multiple Vulnerabilities | Nessus | Windows | high |
3099 | Mozilla Firefox < 1.0.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3067 | Mozilla Firefox < 1.7.10 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
3066 | Mozilla Firefox < 1.0.5 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
18277 | Mandrake Linux Security Advisory : mozilla (MDKSA-2005:088) | Nessus | Mandriva Local Security Checks | high |
2902 | Mozilla Firefox < 1.7.8 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2887 | Mozilla Firefox < 1.0.4 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
18162 | RHEL 2.1 / 3 : Mozilla (RHSA-2005:384) | Nessus | Red Hat Local Security Checks | high |
18154 | SUSE-SA:2005:028: Mozilla. Mozilla Firefox | Nessus | SuSE Local Security Checks | high |
18148 | RHEL 4 : Mozilla (RHSA-2005:386) | Nessus | Red Hat Local Security Checks | high |
18109 | RHEL 4 : firefox (RHSA-2005:383) | Nessus | Red Hat Local Security Checks | high |
18090 | GLSA-200504-18 : Mozilla Firefox, Mozilla Suite: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | high |
18065 | Mozilla Browser < 1.7.7 Multiple Vulnerabilities | Nessus | Windows | high |
18064 | Firefox < 1.0.3 Multiple Vulnerabilities | Nessus | Windows | high |
2789 | Mozilla Firefox < 1.7.7 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2788 | Mozilla Firefox < 1.0.3 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2703 | Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities (deprecated) | Nessus Network Monitor | SMTP Clients | medium |
2671 | Mozilla Firefox < 1.7.6 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2652 | Mozilla Firefox < 1.0.1 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | medium |
2603 | MSN Messenger < 6.2.0205 PNG File Remote Overflow (deprecated) | Nessus Network Monitor | Internet Messengers | medium |
2602 | Microsoft Media Player Version 9 PNG Multiple Vulnerabilities (deprecated) | Nessus Network Monitor | Generic | medium |
1775 | Mozilla Firefox XML User Interface Language Browser Interface Spoofing (deprecated) | Nessus Network Monitor | Web Clients | medium |
1773 | Mozilla Firefox < 1.7.1 / Thunderbird < 0.7.1 POP3 Remote Heap Overflow (deprecated) | Nessus Network Monitor | Web Clients | medium |
1772 | Mozilla Firefox < 1.7.1 Cross-Domain Frame Loading Vulnerability (deprecated) | Nessus Network Monitor | Web Clients | medium |
1771 | Mozilla Firefox < 1.7.2 Non-FQDN SSL Certificate Spoofing | Nessus Network Monitor | Web Clients | medium |
1770 | Mozilla Firefox < 1.7.1 SSL Redirect Spoofing | Nessus Network Monitor | Web Clients | medium |
2116 | Mozilla Firefox Input Type HTML Tag Unauthorized Access (deprecated) | Nessus Network Monitor | Web Clients | medium |
801373 | Mozilla XML User Interface Language Browser Interface Spoofing | Log Correlation Engine | Web Clients | medium |
801318 | Mozilla Browser < 1.7.8 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801295 | Mozilla Firefox < 1.0.4 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801294 | Mozilla Browser < 1.7.12 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801293 | Mozilla < 1.7.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801292 | Mozilla Browser < 1.7.2 Non-FQDN SSL Certificate Spoofing | Log Correlation Engine | Web Clients | medium |
801263 | Mozilla < 1.7.1 SSL Redirect Spoofing | Log Correlation Engine | Web Clients | medium |
801257 | Mozilla Browser < 1.7.10 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801229 | Mozilla Browser Input Type HTML Tag Unauthorized Access | Log Correlation Engine | Web Clients | medium |
801228 | Mozilla < 1.7.1 Cross-Domain Frame Loading Vulnerability | Log Correlation Engine | Web Clients | medium |
801221 | Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities | Log Correlation Engine | SMTP Clients | high |
801217 | Mozilla Firefox < 1.0.5 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801215 | Mozilla < 1.7.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
801211 | Mozilla Browser <1.7.1 / Thunderbird < 0.7.1 SendUIDL POP3 Message Handling Remote Heap Overflow | Log Correlation Engine | Web Clients | medium |
800781 | Firefox < 1.0.7 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800777 | Firefox < 1.0.6 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
800745 | Firefox < 1.0.3 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |