CVE-2004-0905
published 2004-09-14CVE-2004-0905: Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and…
PriorityP419medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
3.05%
86.1th percentile
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| conectiva | linux | — | — |
| conectiva | linux | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| netscape | navigator | — | — |
| netscape | navigator | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqjg-fc86-m5cr: Mozilla Firefox before the Preview Release, Mozilla before 1
ghsa_unreviewed·2022-04-29
CVE-2004-0905 [MEDIUM] GHSA-fqjg-fc86-m5cr: Mozilla Firefox before the Preview Release, Mozilla before 1
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
Red Hat
security flaw
vendor_redhat·2004-07-11·CVSS 4.6
CVE-2004-0905 [MEDIUM] security flaw
security flaw
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
No detection rules found.
No public exploits indexed.
http://bugzilla.mozilla.org/show_bug.cgi?id=250862http://marc.info/?l=bugtraq&m=109698896104418&w=2http://marc.info/?l=bugtraq&m=109900315219363&w=2http://security.gentoo.org/glsa/glsa-200409-26.xmlhttp://www.kb.cert.org/vuls/id/651928http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3http://www.novell.com/linux/security/advisories/2004_36_mozilla.htmlhttp://www.securityfocus.com/bid/11177http://www.us-cert.gov/cas/techalerts/TA04-261A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17374https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10378http://bugzilla.mozilla.org/show_bug.cgi?id=250862http://marc.info/?l=bugtraq&m=109698896104418&w=2http://marc.info/?l=bugtraq&m=109900315219363&w=2http://security.gentoo.org/glsa/glsa-200409-26.xmlhttp://www.kb.cert.org/vuls/id/651928http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3http://www.novell.com/linux/security/advisories/2004_36_mozilla.htmlhttp://www.securityfocus.com/bid/11177http://www.us-cert.gov/cas/techalerts/TA04-261A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17374https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10378
2004-09-14
Published