VDB
CVE-2005-1477
CVE-2005-1477
PUBLISHED
CVSS 5.099999904632568 MEDIUM
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.
EPSS 15.24% · 96.7th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
15.24%
96.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| mozilla | firefox | 1.0.3 |
Timeline
- May 9, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
References
- RHSA-2005:435 vendor-advisory
- http://www.mozilla.org/security/announce/mfsa2005-42.html url
- mozilla-javascript-code-execution(20443) vdb
- RHSA-2005:434 vendor-advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=292691 url
- oval:org.mitre.oval:def:9231 vdb
- oval:org.mitre.oval:def:100001 vdb
- 13544 vdb
- ADV-2005-0493 vdb
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt technical
- http://greyhatsecurity.org/firefox.htm exploit
- http://marc.info/?l=full-disclosure&m=111556301530553&w=2 technical
- http://www.kb.cert.org/vuls/id/648758 advisory
- http://greyhatsecurity.org/vulntests/ffrc.htm exploit
- http://marc.info/?l=full-disclosure&m=111553138007647&w=2 technical
- http://secunia.com/advisories/15292 patch
- http://securitytracker.com/id?1013913 technical
- https://bugzilla.mozilla.org/show_bug.cgi?id=293302 technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-1477 advisory
- http://www.securityfocus.com/bid/15495 url