CVE-2005-2707

MEDIUM

Description

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.

References

ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt

http://secunia.com/advisories/16911

http://secunia.com/advisories/16917

http://secunia.com/advisories/16977

http://secunia.com/advisories/17014

http://secunia.com/advisories/17026

http://secunia.com/advisories/17042

http://secunia.com/advisories/17090

http://secunia.com/advisories/17149

http://secunia.com/advisories/17263

http://secunia.com/advisories/17284

http://secunia.com/advisories/19823

http://securitytracker.com/id?1014954

http://www.debian.org/security/2005/dsa-838

http://www.debian.org/security/2005/dsa-866

http://www.debian.org/security/2005/dsa-868

http://www.mandriva.com/security/advisories?name=MDKSA-2005:169

http://www.mandriva.com/security/advisories?name=MDKSA-2005:170

http://www.mandriva.com/security/advisories?name=MDKSA-2005:174

http://www.mozilla.org/security/announce/mfsa2005-59.html

http://www.novell.com/linux/security/advisories/2005_58_mozilla.html

http://www.novell.com/linux/security/advisories/2006_04_25.html

http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00004.html

http://www.redhat.com/support/errata/RHSA-2005-785.html

http://www.redhat.com/support/errata/RHSA-2005-789.html

http://www.redhat.com/support/errata/RHSA-2005-791.html

http://www.securityfocus.com/bid/14919

http://www.securityfocus.com/bid/15495

http://www.vupen.com/english/advisories/2005/1824

https://exchange.xforce.ibmcloud.com/vulnerabilities/22380

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11130

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1197

Details

Source: MITRE

Published: 2005-09-23

Updated: 2017-10-11

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Tenable Plugins

View all (55 total)

IDNameProductFamilySeverity
21964CentOS 4 : thunderbird (CESA-2005:791)NessusCentOS Local Security Checks
high
21963CentOS 4 : firefox (CESA-2005:785)NessusCentOS Local Security Checks
high
21859CentOS 3 / 4 : Mozilla (CESA-2005:789)NessusCentOS Local Security Checks
high
21473FreeBSD : firefox & mozilla -- multiple vulnerabilities (8f5dd74b-2c61-11da-a263-0001020eed82)NessusFreeBSD Local Security Checks
high
20616Ubuntu 4.10 / 5.04 : mozilla-thunderbird vulnerabilities (USN-200-1)NessusUbuntu Local Security Checks
high
20597Ubuntu 4.10 / 5.04 : mozilla, mozilla-firefox vulnerabilities (USN-186-1)NessusUbuntu Local Security Checks
high
20428Mandrake Linux Security Advisory : mozilla-thunderbird (MDKSA-2005:174)NessusMandriva Local Security Checks
high
20425MDKSA-2005:169 : mozilla-firefoxNessusMandriva Local Security Checks
high
20071Debian DSA-868-1 : mozilla-thunderbird - several vulnerabilitiesNessusDebian Local Security Checks
high
20063Debian DSA-866-1 : mozilla - several vulnerabilitiesNessusDebian Local Security Checks
high
19995RHEL 4 : thunderbird (RHSA-2005:791)NessusRed Hat Local Security Checks
high
19923Mandrake Linux Security Advisory : mozilla (MDKSA-2005:170)NessusMandriva Local Security Checks
high
19837RHEL 2.1 / 3 / 4 : mozilla (RHSA-2005:789)NessusRed Hat Local Security Checks
high
19835RHEL 4 : firefox (RHSA-2005:785)NessusRed Hat Local Security Checks
high
19810GLSA-200509-11 : Mozilla Suite, Mozilla Firefox: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
19807Debian DSA-838-1 : mozilla-firefox - multiple vulnerabilitiesNessusDebian Local Security Checks
high
3239Mozilla Firefox < 1.0.7 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
3238Mozilla Firefox < 1.7.12 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
19719Firefox < 1.0.7 Multiple VulnerabilitiesNessusWindows
high
19718Mozilla Browser < 1.7.12 Multiple VulnerabilitiesNessusWindows
high
3099Mozilla Firefox < 1.0.6 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
3067Mozilla Firefox < 1.7.10 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
3066Mozilla Firefox < 1.0.5 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2902Mozilla Firefox < 1.7.8 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2887Mozilla Firefox < 1.0.4 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2789Mozilla Firefox < 1.7.7 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2788Mozilla Firefox < 1.0.3 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2703Mozilla Thunderbird < 1.0.2 Multiple Vulnerabilities (deprecated)Nessus Network MonitorSMTP Clients
medium
2671Mozilla Firefox < 1.7.6 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2652Mozilla Firefox < 1.0.1 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
medium
2603MSN Messenger < 6.2.0205 PNG File Remote Overflow (deprecated)Nessus Network MonitorInternet Messengers
medium
2602Microsoft Media Player Version 9 PNG Multiple Vulnerabilities (deprecated)Nessus Network MonitorGeneric
medium
1775Mozilla Firefox XML User Interface Language Browser Interface Spoofing (deprecated)Nessus Network MonitorWeb Clients
medium
1773Mozilla Firefox < 1.7.1 / Thunderbird < 0.7.1 POP3 Remote Heap Overflow (deprecated)Nessus Network MonitorWeb Clients
medium
1772Mozilla Firefox < 1.7.1 Cross-Domain Frame Loading Vulnerability (deprecated)Nessus Network MonitorWeb Clients
medium
1771Mozilla Firefox < 1.7.2 Non-FQDN SSL Certificate SpoofingNessus Network MonitorWeb Clients
medium
1770Mozilla Firefox < 1.7.1 SSL Redirect SpoofingNessus Network MonitorWeb Clients
medium
2116Mozilla Firefox Input Type HTML Tag Unauthorized Access (deprecated)Nessus Network MonitorWeb Clients
medium
801373Mozilla XML User Interface Language Browser Interface SpoofingLog Correlation EngineWeb Clients
medium
801318Mozilla Browser < 1.7.8 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801295Mozilla Firefox < 1.0.4 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801294Mozilla Browser < 1.7.12 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801293Mozilla < 1.7.7 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801292Mozilla Browser < 1.7.2 Non-FQDN SSL Certificate SpoofingLog Correlation EngineWeb Clients
medium
801263Mozilla < 1.7.1 SSL Redirect SpoofingLog Correlation EngineWeb Clients
medium
801257Mozilla Browser < 1.7.10 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801229Mozilla Browser Input Type HTML Tag Unauthorized AccessLog Correlation EngineWeb Clients
medium
801228Mozilla < 1.7.1 Cross-Domain Frame Loading VulnerabilityLog Correlation EngineWeb Clients
medium
801221Mozilla Thunderbird < 1.0.2 Multiple VulnerabilitiesLog Correlation EngineSMTP Clients
high
801217Mozilla Firefox < 1.0.5 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801215Mozilla < 1.7.6 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
801211Mozilla Browser <1.7.1 / Thunderbird < 0.7.1 SendUIDL POP3 Message Handling Remote Heap OverflowLog Correlation EngineWeb Clients
medium
800781Firefox < 1.0.7 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800777Firefox < 1.0.6 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high
800745Firefox < 1.0.3 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
high