CVE-2005-1477
Summary
| CVE | CVE-2005-1477 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-05-09 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site. |
Risk And Classification
Primary CVSS: v2.0 5.1 from [email protected]
AV:N/AC:H/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MFSA 2005-42: Code execution via javascript: IconURL | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| Firefox Full Remote Compromise | af854a3a-2127-422b-91ae-364da2661108 | greyhatsecurity.org | Exploit |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Secunia - Advisories - Mozilla Firefox Two Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch |
| ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | |
| Mozilla Firefox Install Method Remote Arbitrary Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| GREYHATSECURITY.ORG | af854a3a-2127-422b-91ae-364da2661108 | greyhatsecurity.org | Exploit |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| US-CERT Vulnerability Note VU#648758 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| 292691 – Full Remote Compromise using some of my previous vulns | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 293302 – Firefox 1.0.3 Critical Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| '[Full-disclosure] Firefox Remote Compromise Technical Details' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| '[Full-disclosure] Firefox Remote Compromise Leaked' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - Firefox onload() History Access Bug and Install Function Scripting Execution Flaw Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.