CVE-2005-2269
Summary
| CVE | CVE-2005-2269 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-07-13 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing"). |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 0.10 | All | All | All |
| Application | Mozilla | Firefox | 0.10.1 | All | All | All |
| Application | Mozilla | Firefox | 0.8 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | rc | All | All |
| Application | Mozilla | Firefox | 0.9.1 | All | All | All |
| Application | Mozilla | Firefox | 0.9.2 | All | All | All |
| Application | Mozilla | Firefox | 0.9.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0 | All | All | All |
| Application | Mozilla | Firefox | 1.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0.4 | All | All | All |
| Application | Mozilla | Mozilla | 1.3 | All | All | All |
| Application | Mozilla | Mozilla | 1.4 | All | All | All |
| Application | Mozilla | Mozilla | 1.4 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.4.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.5 | All | All | All |
| Application | Mozilla | Mozilla | 1.5 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.5 | rc1 | All | All |
| Application | Mozilla | Mozilla | 1.5 | rc2 | All | All |
| Application | Mozilla | Mozilla | 1.5.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.6 | All | All | All |
| Application | Mozilla | Mozilla | 1.6 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.6 | beta | All | All |
| Application | Mozilla | Mozilla | 1.7 | All | All | All |
| Application | Mozilla | Mozilla | 1.7 | alpha | All | All |
| Application | Mozilla | Mozilla | 1.7 | beta | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc1 | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc2 | All | All |
| Application | Mozilla | Mozilla | 1.7 | rc3 | All | All |
| Application | Mozilla | Mozilla | 1.7.1 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.2 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.3 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.5 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.6 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.7 | All | All | All |
| Application | Mozilla | Mozilla | 1.7.8 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Secunia - Advisories - Firefox Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| MFSA 2005-55: XHTML node spoofing | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | Patch, Vendor Advisory |
| 298892 – Node spoofing (using e.g. XHTML) to bypass security checks | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Exploit, Vendor Advisory |
| 160202 – Mozilla Browsers Frame Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| This domain name is registered with Netim | af854a3a-2127-422b-91ae-364da2661108 | www.networksecurity.fi | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| www.ciac.org/ciac/bulletins/p-252.shtml | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| SUSE update for MozillaThunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Secunia - Advisories - Mozilla Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Secunia - Advisories - Netscape Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Debian -- Security Information -- DSA-810-1 mozilla | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.