Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
CVSS Details
- CVSS 3.1 Base Score: 8.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2005 44 | — | Upgrade to Mozilla Firefox version 1.0.4Upgrade to the latest version of Mozilla Firefox | Jul 25, 2005 | May 12, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-nbUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-trUpgrade mozilla-browserUpgrade mozilla-firefoxUpgrade mozilla-thunderbirdUpgrade mozilla-firefox-locale-ja | Nov 8, 2024 | May 12, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub