CVE-2004-0905Mozilla Firefox vulnerability

5 documents5 sources
Severity
4.6MEDIUMNVD
EPSS
6.6%
top 8.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateApr 29

Description

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages9 packages

NVDmozilla/firefox5 versions+4
NVDmozilla/mozilla16 versions+15
NVDredhat/linux7.3, 9.0+1
NVDconectiva/linux10.0, 9.0+1
NVDsuse/suse_linux6 versions+5

Also affects: Enterprise Linux 2.1, 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fqjg-fc86-m5cr: Mozilla Firefox before the Preview Release, Mozilla before 12022-04-29
CVEList
CVE-2004-0905: Mozilla Firefox before the Preview Release, Mozilla before 12004-09-24

📋Vendor Advisories

1
Red Hat
security flaw2004-07-11

💬Community

1
Bugzilla
CVE-2004-0905 security flaw2018-08-16
CVE-2004-0905 — Mozilla Firefox vulnerability | cvebase