7.5
CVSSv2

CVE-2005-1532

Published: 12/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Firefox prior to 1.0.4 and Mozilla Suite prior to 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote malicious users to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 0.9.1

mozilla firefox 0.9.2

mozilla mozilla 1.4

mozilla mozilla 1.4.1

mozilla mozilla 1.6

mozilla mozilla 1.7.6

mozilla mozilla 1.7.7

mozilla firefox 0.8

mozilla firefox 0.9

mozilla firefox 1.0.3

mozilla mozilla 1.3

mozilla mozilla 1.5

mozilla mozilla 1.7.3

mozilla mozilla 1.7.5

mozilla firefox 0.9.3

mozilla mozilla 1.7

mozilla firefox 0.10

mozilla firefox 0.10.1

mozilla firefox 1.0

mozilla firefox 1.0.1

mozilla firefox 1.0.2

mozilla mozilla 1.5.1

mozilla mozilla 1.7.1

mozilla mozilla 1.7.2

Vendor Advisories

Synopsis mozilla security update Type/Severity Security Advisory: Important Topic Updated mozilla packages that fix various security bugs are now availableThis update has been rated as having important security impact by the RedHat Security Response Team[Updated 24 May 2005]This erratum now includes updat ...
Synopsis firefox security update Type/Severity Security Advisory: Important Topic Updated firefox packages that fix various security bugs are now availableThis update has been rated as having important security impact by the RedHat Security Response Team Description Mozilla Firefox is an ...
Synopsis thunderbird security update Type/Severity Security Advisory: Important Topic Updated thunderbird package that fixes various bugs is now available forRed Hat Enterprise Linux 4This update has been rated as having important security impact by the RedHat Security Response Team Description ...
Several problems have been discovered in Mozilla Thunderbird, the standalone mail client of the Mozilla suite The Common Vulnerabilities and Exposures project identifies the following problems: CAN-2005-0989 Remote attackers could read portions of heap memory into a Javascript string via the lambda replace method CAN-2005-1159 The Ja ...
It was discovered that a malicious website could inject arbitrary scripts into a target site by loading it into a frame and navigating back to a previous Javascript URL that contained an eval() call This could be used to steal cookies or other confidential data from the target site If the target site is allowed to raise the install confirmation d ...
Secuniacom reported that one of the recent security patches in Firefox reintroduced the frame injection patch that was originally known as CAN-2004-0718 This allowed a malicious web site to spoof the contents of other web sites (CAN-2005-1937) ...
USN-149-1 fixed some vulnerabilities in the Ubuntu 504 (Hoary Hedgehog) version of Firefox The version shipped with Ubuntu 410 (Warty Warthog) is also vulnerable to these flaws, so it needs to be upgraded as well Please see ...
Vladimir V Perepelitsa discovered a bug in Thunderbird’s handling of anonymous functions during regular expression string replacement A malicious HTML email could exploit this to capture a random block of client memory (CAN-2005-0989) ...

Exploits

source: wwwsecurityfocuscom/bid/13645/info Mozilla Suite and Mozilla Firefox are affected by a code-execution vulnerability This issue is due to a failure in the application to properly verify Document Object Model (DOM) property values An attacker may leverage this issue to execute arbitrary code with the privileges of the user that a ...