Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CAN-2005-1477
Description:The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-1477
BugTraq ID: 13544
http://www.securityfocus.com/bid/13544
BugTraq ID: 15495
http://www.securityfocus.com/bid/15495
CERT/CC vulnerability note: VU#648758
http://www.kb.cert.org/vuls/id/648758
http://marc.info/?l=full-disclosure&m=111553138007647&w=2
http://marc.info/?l=full-disclosure&m=111556301530553&w=2
http://greyhatsecurity.org/firefox.htm
http://greyhatsecurity.org/vulntests/ffrc.htm
https://bugzilla.mozilla.org/show_bug.cgi?id=292691
https://bugzilla.mozilla.org/show_bug.cgi?id=293302
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231
RedHat Security Advisories: RHSA-2005:434
http://www.redhat.com/support/errata/RHSA-2005-434.html
RedHat Security Advisories: RHSA-2005:435
http://www.redhat.com/support/errata/RHSA-2005-435.html
SCO Security Bulletin: SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://securitytracker.com/id?1013913
http://secunia.com/advisories/15292
http://www.vupen.com/english/advisories/2005/0493
XForce ISS Database: mozilla-javascript-code-execution(20443)
https://exchange.xforce.ibmcloud.com/vulnerabilities/20443




© 1998-2025 E-Soft Inc. All rights reserved.