The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-firefoxUpgrade firefox | Dec 10, 2025 | Apr 16, 2005 |
| Mfsa2005 34 | — | Upgrade to Mozilla Firefox version 1.0.3Upgrade to the latest version of Mozilla Firefox | Jul 28, 2005 | Apr 18, 2005 |
| Ubuntu | — | Upgrade mozilla-psmUpgrade mozilla-browserUpgrade firefoxUpgrade mozilla-firefox-locale-jaUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-nbUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-trUpgrade mozilla-mailnews | Nov 8, 2024 | Apr 18, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub