Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2005 12 | — | Upgrade to Mozilla Firefox version 1.0.0Upgrade to the latest version of Mozilla Firefox | Jul 28, 2005 | May 26, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-jaUpgrade mozilla-firefox-locale-nbUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-tr | Nov 8, 2024 | May 26, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub