VDB
CVE-2005-1156
CVE-2005-1156
PUBLISHED
CVSS 7.5 HIGH
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."
EPSS 2.34% · 82.3th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
2.34%
82.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| netscape | navigator | 7.2 |
| mozilla | firefox | 0.8, 0.9, 0.9 |
| mozilla | mozilla | 1.7, 1.7, 1.7 |
| n/a | n/a | n/a |
Timeline
- Apr 18, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- oval:org.mitre.oval:def:11230 vdb
- http://www.mikx.de/firesearching/ url
- 14938 third-party-advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=290037 url
- 14992 third-party-advisory
- mozilla-plugin-xss(20125) vdb
- 13211 vdb
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt technical
- http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml patch
- http://www.securityfocus.com/bid/15495 technical
- http://www.mozilla.org/security/announce/mfsa2005-38.html advisory
- http://www.redhat.com/support/errata/RHSA-2005-386.html patch
- https://nvd.nist.gov/vuln/detail/CVE-2005-1156 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100020 url
- http://secunia.com/advisories/14996 url
- http://securitytracker.com/id?1013745 url
- http://www.mikx.de/firesearching url
- http://www.redhat.com/support/errata/RHSA-2005-383.html url
- http://www.redhat.com/support/errata/RHSA-2005-384.html url