VDB
CVE-2005-2701
CVE-2005-2701
PUBLISHED
CVSS 7.5 HIGH
Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.
EPSS 6.86% · 93.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
6.86%
93.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mozilla | mozilla_suite | 0, 1.7.10, 1.7.8 |
| n/a | n/a | n/a |
| mozilla | firefox | 1.0.4, 1.0.5, 1.0.3 |
Timeline
- Sep 23, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- DSA-868 vendor-advisory
- FLSA-2006:168375 vendor-advisory
- SCOSA-2005.49 vendor-advisory
- 1014954 vdb
- USN-200-1 vendor-advisory
- http://www.mozilla.org/security/announce/mfsa2005-58.html url
- RHSA-2005:785 vendor-advisory
- 19643 vdb
- 15495 vdb
- RHSA-2005:789 vendor-advisory
- oval:org.mitre.oval:def:1480 vdb
- 14916 vdb
- 17149 third-party-advisory
- 17014 third-party-advisory
- 16911 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-2701 advisory
- http://secunia.com/advisories/16977 url
- http://secunia.com/advisories/17263 url
- http://secunia.com/advisories/17284 url
- http://www.debian.org/security/2005/dsa-866 url
…and 10 more