The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mozilla-gtk1Upgrade mozilla-embeddedUpgrade ja-mozillafirebird-gtk2Upgrade el-linux-mozillafirebirdUpgrade linux-mozillaUpgrade ja-linux-mozillafirebird-gtk1Upgrade pt_BR-netscape7Upgrade mozillaUpgrade linux-phoenixUpgrade netscape7Upgrade ru-linux-mozillafirebirdUpgrade firefoxUpgrade de-linux-mozillafirebirdUpgrade mozilla-firebirdUpgrade mozilla-thunderbirdUpgrade linux-mozillafirebirdUpgrade mozilla-gtk2Upgrade de-linux-netscapeUpgrade fr-netscape7Upgrade mozilla+ipv6Upgrade linux-netscapeUpgrade fr-linux-netscapeUpgrade linux-firefoxUpgrade zhTW-linux-mozillafirebirdUpgrade ja-linux-netscapeUpgrade de-netscape7Upgrade mozilla-gtkUpgrade ja-netscape7Upgrade phoenixUpgrade linux-mozilla-develUpgrade zhCN-linux-mozillafirebird | Dec 10, 2025 | Jul 16, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-nbUpgrade mozilla-browserUpgrade mozilla-firefox-locale-trUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-ja | Nov 8, 2024 | Jul 13, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub