CVE-2005-1532
Summary
| CVE | CVE-2005-1532 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-05-12 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 0.10 | All | All | All |
| Application | Mozilla | Firefox | 0.10.1 | All | All | All |
| Application | Mozilla | Firefox | 0.8 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | rc | All | All |
| Application | Mozilla | Firefox | 0.9.1 | All | All | All |
| Application | Mozilla | Firefox | 0.9.2 | All | All | All |
| Application | Mozilla | Firefox | 0.9.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0 | All | All | All |
| Application | Mozilla | Firefox | 1.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.0.3 | All | All | All |
| Application | Mozilla | Mozilla | 1.3 | All | All | All |
| Application | Mozilla | Mozilla | 1.4 | All | All | All |
| Application | Mozilla | Mozilla | 1.4 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.4.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.5 | All | All | All |
| Application | Mozilla | Mozilla | 1.5 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.5 | rc1 | All | All |
| Application | Mozilla | Mozilla | 1.5 | rc2 | All | All |
| Application | Mozilla | Mozilla | 1.5.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.6 | All | All | All |
| Application | Mozilla | Mozilla | 1.6 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.6 | beta | All | All |
| Application | Mozilla | Mozilla | 1.7 | All | All | All |
| Application | Mozilla | Mozilla | 1.7 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.7 | beta | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc1 | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc2 | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc3 | All | All |
| Application | Mozilla | Mozilla | 1.7.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.2 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.3 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.5 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.6 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mozilla Suite And Firefox DOM Property Overrides Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - Mozilla Suite Lets Remote Users Invoke eval and Script Objects With Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| SUSE update for MozillaThunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| MFSA 2005-44: Privilege escalation via non-DOM property overrides | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.sco.com | |
| SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SecurityTracker.com Archives - Firefox Lets Remote Users Invoke eval and Script Objects With Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.