VDB
CVE-2005-1160
CVE-2005-1160
PUBLISHED
CVSS 5.099999904632568 MEDIUM
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
EPSS 2.72% · 84.6th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
2.72%
84.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| mozilla | firefox | 0.9.1, 0.8, 0.9 |
| mozilla | mozilla | 1.7, 1.7, 1.4 |
Timeline
- Apr 18, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 14992 third-party-advisory
- SCOSA-2005.49 vendor-advisory
- http://www.mozilla.org/security/announce/mfsa2005-41.html url
- RHSA-2005:384 vendor-advisory
- RHSA-2005:383 vendor-advisory
- SUSE-SA:2006:022 vendor-advisory
- 19823 third-party-advisory
- 14938 third-party-advisory
- http://www.gentoo.org/security/en/glsa/glsa-200504-18.xml patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=289083 patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=289961 patch
- http://www.redhat.com/support/errata/RHSA-2005-386.html patch
- http://www.securityfocus.com/bid/15495 technical
- https://bugzilla.mozilla.org/show_bug.cgi?id=289074 patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100017 technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11291 technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-1160 advisory
- http://www.redhat.com/support/errata/RHSA-2005-601.html url
- http://www.securityfocus.com/bid/13233 url