Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54400
Category:Fedora Local Security Checks
Title:Fedora Core 4 FEDORA-2005-619 (mozilla)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to mozilla
announced via advisory FEDORA-2005-619.

Mozilla is an open-source Web browser, designed for standards
compliance, performance, and portability.

A bug was found in the way Mozilla handled synthetic events. It is possible
that Web content could generate events such as keystrokes or mouse clicks
that could be used to steal data or execute malicious Javascript code. The
Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned
the name CVE-2005-2260 to this issue.

A bug was found in the way Mozilla executed Javascript in XBL controls. It
is possible for a malicious webpage to leverage this vulnerability to
execute other JavaScript based attacks even when JavaScript is disabled.
(CVE-2005-2261)

A bug was found in the way Mozilla installed its extensions. If a user can
be tricked into visiting a malicious webpage, it may be possible to obtain
sensitive information such as cookies or passwords. (CVE-2005-2263)

A bug was found in the way Mozilla handled certain Javascript functions. It
is possible for a malicious webpage to crash the browser by executing
malformed Javascript code. (CVE-2005-2265)

A bug was found in the way Mozilla handled multiple frame domains. It is
possible for a frame as part of a malicious website to inject content into
a frame that belongs to another domain. This issue was previously fixed as
CVE-2004-0718 but was accidentally disabled. (CVE-2005-1937)

A bug was found in the way Mozilla handled child frames. It is possible for
a malicious framed page to steal sensitive information from its parent
page. (CVE-2005-2266)

A bug was found in the way Mozilla opened URLs from media players. If a
media player opens a URL which is Javascript, the Javascript executes
with access to the currently open webpage. (CVE-2005-2267)

A design flaw was found in the way Mozilla displayed alerts and prompts.
Alerts and prompts were given the generic title [JavaScript Application]
which prevented a user from knowing which site created them. (CVE-2005-2268)

A bug was found in the way Mozilla handled DOM node names. It is possible
for a malicious site to overwrite a DOM node name, allowing certain
privileged chrome actions to execute the malicious Javascript. (CVE-2005-2269)

A bug was found in the way Mozilla cloned base objects. It is possible for
Web content to traverse the prototype chain to gain access to privileged
chrome objects. (CVE-2005-2270)

Users of Mozilla are advised to upgrade to these updated packages, which
contain Mozilla version 1.7.10 and are not vulnerable to these issues.
* Tue Jul 19 2005 Christopher Aillon 37:1.7.10-1.5.1
- Update to 1.7.10
- Fix a crash on 64bit platforms (#160330)

Solution: Apply the appropriate updates.

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/4/

This update can also be installed with the Update Agent
you can
launch the Update Agent with the 'up2date' command.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2005-619

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2260
14242
http://www.securityfocus.com/bid/14242
16043
http://secunia.com/advisories/16043
16044
http://secunia.com/advisories/16044
16059
http://secunia.com/advisories/16059
ADV-2005-1075
http://www.vupen.com/english/advisories/2005/1075
DSA-810
http://www.debian.org/security/2005/dsa-810
FLSA:160202
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202
P-252
http://www.ciac.org/ciac/bulletins/p-252.shtml
RHSA-2005:586
http://www.redhat.com/support/errata/RHSA-2005-586.html
RHSA-2005:587
http://www.redhat.com/support/errata/RHSA-2005-587.html
SUSE-SA:2005:045
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
SUSE-SR:2005:018
http://www.novell.com/linux/security/advisories/2005_18_sr.html
http://bugzilla.mozilla.org/show_bug.cgi?id=289940
http://www.mozilla.org/security/announce/mfsa2005-45.html
http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
oval:org.mitre.oval:def:100013
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100013
oval:org.mitre.oval:def:10132
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10132
oval:org.mitre.oval:def:1226
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1226
oval:org.mitre.oval:def:742
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A742
Common Vulnerability Exposure (CVE) ID: CVE-2005-2261
19823
http://secunia.com/advisories/19823
RHSA-2005:601
http://www.redhat.com/support/errata/RHSA-2005-601.html
SUSE-SA:2006:022
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.mozilla.org/security/announce/mfsa2005-46.html
https://bugzilla.mozilla.org/show_bug.cgi?id=292589
https://bugzilla.mozilla.org/show_bug.cgi?id=292591
oval:org.mitre.oval:def:100012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100012
oval:org.mitre.oval:def:10947
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10947
oval:org.mitre.oval:def:1348
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1348
oval:org.mitre.oval:def:808
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A808
Common Vulnerability Exposure (CVE) ID: CVE-2005-2263
http://www.mozilla.org/security/announce/mfsa2005-48.html
https://bugzilla.mozilla.org/show_bug.cgi?id=293331
oval:org.mitre.oval:def:100010
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100010
oval:org.mitre.oval:def:100016
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100016
oval:org.mitre.oval:def:11629
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11629
oval:org.mitre.oval:def:1281
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1281
oval:org.mitre.oval:def:1311
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1311
Common Vulnerability Exposure (CVE) ID: CVE-2005-2265
http://www.mozilla.org/security/announce/mfsa2005-50.html
https://bugzilla.mozilla.org/show_bug.cgi?id=295854
oval:org.mitre.oval:def:100008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100008
oval:org.mitre.oval:def:10397
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10397
oval:org.mitre.oval:def:417
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A417
oval:org.mitre.oval:def:781
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A781
Common Vulnerability Exposure (CVE) ID: CVE-2004-0718
BugTraq ID: 15495
http://www.securityfocus.com/bid/15495
Debian Security Information: DSA-777 (Google Search)
http://www.debian.org/security/2005/dsa-777
Debian Security Information: DSA-810 (Google Search)
http://marc.info/?l=bugtraq&m=109900315219363&w=2
http://www.mandriva.com/security/advisories?name=MDKSA-2004:082
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4756
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9997
http://www.redhat.com/support/errata/RHSA-2004-421.html
SCO Security Bulletin: SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
http://secunia.com/advisories/11978
SuSE Security Announcement: SUSE-SA:2004:036 (Google Search)
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
XForce ISS Database: http-frame-spoof(1598)
https://exchange.xforce.ibmcloud.com/vulnerabilities/1598
Common Vulnerability Exposure (CVE) ID: CVE-2005-1937
BugTraq ID: 14242
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100007
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10633
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A637
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A759
http://secunia.com/advisories/15601
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101952-1
SuSE Security Announcement: SUSE-SA:2005:045 (Google Search)
SuSE Security Announcement: SUSE-SR:2005:018 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2005-2266
15549
http://secunia.com/advisories/15549
15551
http://secunia.com/advisories/15551
15553
http://secunia.com/advisories/15553
http://www.mozilla.org/security/announce/mfsa2005-52.html
mozilla-frame-topfocus-xss(21332)
https://exchange.xforce.ibmcloud.com/vulnerabilities/21332
oval:org.mitre.oval:def:100107
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100107
oval:org.mitre.oval:def:10712
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10712
oval:org.mitre.oval:def:1415
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1415
oval:org.mitre.oval:def:773
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A773
Common Vulnerability Exposure (CVE) ID: CVE-2005-2267
1014469
http://securitytracker.com/id?1014469
http://www.mozilla.org/security/announce/mfsa2005-53.html
https://bugzilla.mozilla.org/show_bug.cgi?id=298255
oval:org.mitre.oval:def:100006
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100006
oval:org.mitre.oval:def:1073
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1073
oval:org.mitre.oval:def:11334
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11334
oval:org.mitre.oval:def:1172
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1172
Common Vulnerability Exposure (CVE) ID: CVE-2005-2268
15489
http://secunia.com/advisories/15489
http://secunia.com/multiple_browsers_dialog_origin_vulnerability_test/
http://www.mozilla.org/security/announce/mfsa2005-54.html
oval:org.mitre.oval:def:100005
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100005
oval:org.mitre.oval:def:10517
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10517
oval:org.mitre.oval:def:1268
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1268
oval:org.mitre.oval:def:1313
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1313
Common Vulnerability Exposure (CVE) ID: CVE-2005-2269
http://www.mozilla.org/security/announce/mfsa2005-55.html
https://bugzilla.mozilla.org/show_bug.cgi?id=298892
oval:org.mitre.oval:def:100004
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100004
oval:org.mitre.oval:def:100011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100011
oval:org.mitre.oval:def:1258
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1258
oval:org.mitre.oval:def:729
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A729
oval:org.mitre.oval:def:9777
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9777
Common Vulnerability Exposure (CVE) ID: CVE-2005-2270
1014470
http://securitytracker.com/id?1014470
VU#652366
http://www.kb.cert.org/vuls/id/652366
http://www.mozilla.org/security/announce/mfsa2005-56.html
https://bugzilla.mozilla.org/show_bug.cgi?id=294795
https://bugzilla.mozilla.org/show_bug.cgi?id=294799
https://bugzilla.mozilla.org/show_bug.cgi?id=295011
https://bugzilla.mozilla.org/show_bug.cgi?id=296397
oval:org.mitre.oval:def:100003
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100003
oval:org.mitre.oval:def:11751
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11751
oval:org.mitre.oval:def:550
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A550
oval:org.mitre.oval:def:817
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A817
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.