{"api_version":"1","generated_at":"2026-07-23T12:23:23+00:00","cve":"CVE-2005-1477","urls":{"html":"https://cve.report/CVE-2005-1477","api":"https://cve.report/api/cve/CVE-2005-1477.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1477","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1477"},"summary":{"title":"CVE-2005-1477","description":"The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-09 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.1","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.mozilla.org/security/announce/mfsa2005-42.html","name":"http://www.mozilla.org/security/announce/mfsa2005-42.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MFSA 2005-42: Code execution via javascript: IconURL","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://greyhatsecurity.org/vulntests/ffrc.htm","name":"http://greyhatsecurity.org/vulntests/ffrc.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Firefox Full Remote Compromise","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15292","name":"http://secunia.com/advisories/15292","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Secunia - Advisories - Mozilla Firefox Two Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt","name":"ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/13544","name":"http://www.securityfocus.com/bid/13544","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mozilla Firefox Install Method Remote Arbitrary Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/15495","name":"http://www.securityfocus.com/bid/15495","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released - Multiple Vulnerabilities Fixed","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://greyhatsecurity.org/firefox.htm","name":"http://greyhatsecurity.org/firefox.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"GREYHATSECURITY.ORG","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-434.html","name":"http://www.redhat.com/support/errata/RHSA-2005-434.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2005-435.html","name":"http://www.redhat.com/support/errata/RHSA-2005-435.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/648758","name":"http://www.kb.cert.org/vuls/id/648758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#648758","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=292691","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=292691","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"292691 – Full Remote Compromise using some of my previous vulns","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/0493","name":"http://www.vupen.com/english/advisories/2005/0493","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=293302","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=293302","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"293302 – Firefox 1.0.3 Critical Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=full-disclosure&m=111556301530553&w=2","name":"http://marc.info/?l=full-disclosure&m=111556301530553&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[Full-disclosure] Firefox Remote Compromise Technical Details' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=full-disclosure&m=111553138007647&w=2","name":"http://marc.info/?l=full-disclosure&m=111553138007647&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'[Full-disclosure] Firefox Remote Compromise Leaked' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1013913","name":"http://securitytracker.com/id?1013913","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Firefox onload() History Access Bug and Install Function Scripting Execution Flaw Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20443","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20443","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1477","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1477","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1477","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"1.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:51:50.409Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=292691"},{"name":"SCOSA-2005.49","tags":["vendor-advisory","x_refsource_SCO","x_transferred"],"url":"ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt"},{"name":"oval:org.mitre.oval:def:9231","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231"},{"name":"RHSA-2005:435","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2005-435.html"},{"name":"1013913","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1013913"},{"name":"15292","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15292"},{"name":"15495","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15495"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=293302"},{"name":"20050508 Firefox Remote Compromise Technical Details","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://marc.info/?l=full-disclosure&m=111556301530553&w=2"},{"name":"oval:org.mitre.oval:def:100001","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001"},{"name":"13544","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13544"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://greyhatsecurity.org/vulntests/ffrc.htm"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/mfsa2005-42.html"},{"name":"mozilla-javascript-code-execution(20443)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20443"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://greyhatsecurity.org/firefox.htm"},{"name":"RHSA-2005:434","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2005-434.html"},{"name":"ADV-2005-0493","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/0493"},{"name":"VU#648758","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/648758"},{"name":"20050508 Firefox Remote Compromise Leaked","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://marc.info/?l=full-disclosure&m=111553138007647&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-05-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=292691"},{"name":"SCOSA-2005.49","tags":["vendor-advisory","x_refsource_SCO"],"url":"ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt"},{"name":"oval:org.mitre.oval:def:9231","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231"},{"name":"RHSA-2005:435","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2005-435.html"},{"name":"1013913","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1013913"},{"name":"15292","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15292"},{"name":"15495","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15495"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=293302"},{"name":"20050508 Firefox Remote Compromise Technical Details","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://marc.info/?l=full-disclosure&m=111556301530553&w=2"},{"name":"oval:org.mitre.oval:def:100001","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001"},{"name":"13544","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13544"},{"tags":["x_refsource_MISC"],"url":"http://greyhatsecurity.org/vulntests/ffrc.htm"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/mfsa2005-42.html"},{"name":"mozilla-javascript-code-execution(20443)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20443"},{"tags":["x_refsource_MISC"],"url":"http://greyhatsecurity.org/firefox.htm"},{"name":"RHSA-2005:434","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2005-434.html"},{"name":"ADV-2005-0493","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/0493"},{"name":"VU#648758","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/648758"},{"name":"20050508 Firefox Remote Compromise Leaked","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://marc.info/?l=full-disclosure&m=111553138007647&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1477","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=292691","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=292691"},{"name":"SCOSA-2005.49","refsource":"SCO","url":"ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt"},{"name":"oval:org.mitre.oval:def:9231","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231"},{"name":"RHSA-2005:435","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2005-435.html"},{"name":"1013913","refsource":"SECTRACK","url":"http://securitytracker.com/id?1013913"},{"name":"15292","refsource":"SECUNIA","url":"http://secunia.com/advisories/15292"},{"name":"15495","refsource":"BID","url":"http://www.securityfocus.com/bid/15495"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=293302","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=293302"},{"name":"20050508 Firefox Remote Compromise Technical Details","refsource":"FULLDISC","url":"http://marc.info/?l=full-disclosure&m=111556301530553&w=2"},{"name":"oval:org.mitre.oval:def:100001","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001"},{"name":"13544","refsource":"BID","url":"http://www.securityfocus.com/bid/13544"},{"name":"http://greyhatsecurity.org/vulntests/ffrc.htm","refsource":"MISC","url":"http://greyhatsecurity.org/vulntests/ffrc.htm"},{"name":"http://www.mozilla.org/security/announce/mfsa2005-42.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/mfsa2005-42.html"},{"name":"mozilla-javascript-code-execution(20443)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/20443"},{"name":"http://greyhatsecurity.org/firefox.htm","refsource":"MISC","url":"http://greyhatsecurity.org/firefox.htm"},{"name":"RHSA-2005:434","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2005-434.html"},{"name":"ADV-2005-0493","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/0493"},{"name":"VU#648758","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/648758"},{"name":"20050508 Firefox Remote Compromise Leaked","refsource":"FULLDISC","url":"http://marc.info/?l=full-disclosure&m=111553138007647&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1477","datePublished":"2005-05-09T04:00:00.000Z","dateReserved":"2005-05-09T00:00:00.000Z","dateUpdated":"2024-08-07T21:51:50.409Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-09 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:*","matchCriteriaId":"0EDBAC37-9D08-44D1-B279-BC6ACF126CAF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1477","Ordinal":"1","Title":"CVE-2005-1477","CVE":"CVE-2005-1477","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1477","Ordinal":"1","NoteData":"The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.","Type":"Description","Title":"CVE-2005-1477"},{"CveYear":"2005","CveId":"1477","Ordinal":"2","NoteData":"2005-05-09","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1477","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}