Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-0401
Description:FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
Test IDs: 1.3.6.1.4.1.25623.1.0.52581   1.3.6.1.4.1.25623.1.0.51925  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-0401
12885
http://www.securityfocus.com/bid/12885
14654
http://secunia.com/advisories/14654
20050324 Firescrolling 2 [Firefox 1.0.1]
http://marc.info/?l=bugtraq&m=111168413007891&w=2
ADV-2005-0296
http://www.vupen.com/english/advisories/2005/0296
GLSA-200503-30
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
RHSA-2005:335
http://www.redhat.com/support/errata/RHSA-2005-335.html
RHSA-2005:336
http://www.redhat.com/support/errata/RHSA-2005-336.html
RHSA-2005:384
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://mikx.de/firescrolling2/
http://mikx.de/firescrolling2/
http://www.mozilla.org/security/announce/mfsa2005-32.html
http://www.mozilla.org/security/announce/mfsa2005-32.html
oval:org.mitre.oval:def:100026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100026
oval:org.mitre.oval:def:9650
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9650




© 1998-2025 E-Soft Inc. All rights reserved.