Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2005 43 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 1.0.4 | Jul 25, 2005 | May 12, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-trUpgrade mozilla-firefox-locale-nbUpgrade mozilla-firefoxUpgrade mozilla-browserUpgrade mozilla-firefox-locale-ja | Nov 8, 2024 | May 12, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub