CVE-2004-0762

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
References
Link Resource
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html
http://bugzilla.mozilla.org/show_bug.cgi?id=162020 Patch Vendor Advisory
http://marc.info/?l=bugtraq&m=109900315219363&w=2
http://secunia.com/advisories/11999/
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
http://www.redhat.com/support/errata/RHSA-2004-421.html
http://www.securityfocus.com/bid/15495
http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/
https://exchange.xforce.ibmcloud.com/vulnerabilities/16623
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10032
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4403
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html
http://bugzilla.mozilla.org/show_bug.cgi?id=162020 Patch Vendor Advisory
http://marc.info/?l=bugtraq&m=109900315219363&w=2
http://secunia.com/advisories/11999/
http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
http://www.redhat.com/support/errata/RHSA-2004-421.html
http://www.securityfocus.com/bid/15495
http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/
https://exchange.xforce.ibmcloud.com/vulnerabilities/16623
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10032
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4403
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt - () ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt -
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html - () http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0264.html -
References () http://bugzilla.mozilla.org/show_bug.cgi?id=162020 - Patch, Vendor Advisory () http://bugzilla.mozilla.org/show_bug.cgi?id=162020 - Patch, Vendor Advisory
References () http://marc.info/?l=bugtraq&m=109900315219363&w=2 - () http://marc.info/?l=bugtraq&m=109900315219363&w=2 -
References () http://secunia.com/advisories/11999/ - () http://secunia.com/advisories/11999/ -
References () http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7 - () http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7 -
References () http://www.novell.com/linux/security/advisories/2004_36_mozilla.html - () http://www.novell.com/linux/security/advisories/2004_36_mozilla.html -
References () http://www.redhat.com/support/errata/RHSA-2004-421.html - () http://www.redhat.com/support/errata/RHSA-2004-421.html -
References () http://www.securityfocus.com/bid/15495 - () http://www.securityfocus.com/bid/15495 -
References () http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/ - () http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/ -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16623 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16623 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10032 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10032 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4403 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4403 -

Information

Published : 2004-08-18 04:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-0762

Mitre link : CVE-2004-0762

CVE.ORG link : CVE-2004-0762


JSON object : View

Products Affected

mozilla

  • firefox
  • mozilla
  • thunderbird