Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade linux-firefox | Dec 10, 2025 | May 3, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Apr 25, 2006 |
| Mfsa2006 30 | — | Upgrade to Mozilla Firefox version 1.5.0.3 | Jun 14, 2012 | Apr 25, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub