The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:56
Type | Values Removed | Values Added |
---|---|---|
References | () ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt - | |
References | () http://secunia.com/advisories/14938 - Patch, Vendor Advisory | |
References | () http://secunia.com/advisories/14992 - Patch, Vendor Advisory | |
References | () http://secunia.com/advisories/19823 - | |
References | () http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml - Patch, Vendor Advisory | |
References | () http://www.mozilla.org/security/announce/mfsa2005-41.html - Vendor Advisory | |
References | () http://www.novell.com/linux/security/advisories/2006_04_25.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2005-383.html - Patch, Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2005-384.html - | |
References | () http://www.redhat.com/support/errata/RHSA-2005-386.html - Patch, Vendor Advisory | |
References | () http://www.redhat.com/support/errata/RHSA-2005-601.html - | |
References | () http://www.securityfocus.com/bid/13233 - | |
References | () http://www.securityfocus.com/bid/15495 - | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=289074 - Patch | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=289083 - Patch | |
References | () https://bugzilla.mozilla.org/show_bug.cgi?id=289961 - Patch | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100017 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11291 - |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:56
NVD link : CVE-2005-1160
Mitre link : CVE-2005-1160
CVE.ORG link : CVE-2005-1160
JSON object : View
Products Affected
mozilla
- mozilla
- firefox
CWE