Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) servers to execute code with elevated privileges via a PAC script that sets the FindProxyForURL function to an eval method on a privileged object.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Jul 27, 2006 |
| Freebsd | — | Upgrade linux-thunderbirdUpgrade mozillaUpgrade linux-mozilla-develUpgrade linux-seamonkeyUpgrade firefoxUpgrade linux-firefoxUpgrade seamonkeyUpgrade linux-firefox-develUpgrade mozilla-thunderbirdUpgrade linux-mozillaUpgrade thunderbird | Dec 10, 2025 | Jul 27, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey. | Oct 30, 2017 | Jul 27, 2006 |
| Ubuntu | — | Upgrade libnspr4Upgrade mozilla-mailnewsUpgrade mozilla-browserUpgrade libnss3Upgrade firefoxUpgrade mozilla-psm | Nov 8, 2024 | Jul 27, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub