Mozilla Firefox < 1.0.2 Multiple Vulnerabilities

Medium Nessus Network Monitor Plugin ID 2704

Synopsis

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Description

The remote host is using Firefox. The remote version of this software contains multiple security flaws that can be exploited by a malicious website. An attacker exploiting one of these flaws would need to be able to either convince a remote user to visit a malicious website or convince the remote user to open an HTML email and save an attachment.
In addition, this version is vulnerable to a remote flaw that could result in arbitrary code execution. Specifically, if a malicious web page is bookmarked as a sidebar panel, the malicious page may open and inject code into privileged pages. An attacker exploiting this flaw would need to be able to convince a user to both visit and bookmark their malicious web page.

Solution

Upgrade to version 1.0.2 or higher.

See Also

http://www.mozilla.org

Plugin Details

Severity: Medium

ID: 2704

File Name: 2704.prm

Family: Web Clients

Published: 2005/03/14

Modified: 2016/11/23

Dependencies: 9131

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 5

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: CVSS2#E:H/RL:U/RC:ND

CVSSv3

Base Score: 5.3

Temporal Score: 5.3

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS3#E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Reference Information

CVE: CVE-2005-0401, CVE-2005-4809, CVE-2005-0402

BID: 12672, 12798, 12884, 12885

OSVDB: 14885, 15009