The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-bin.Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | May 2, 2005 |
| Mfsa2005 41 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 1.0.3 | Jul 26, 2005 | May 2, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-jaUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefoxUpgrade mozilla-thunderbirdUpgrade mozilla-firefox-locale-trUpgrade mozilla-firefox-locale-nb | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub