CVE-2005-1160
published 2005-05-02CVE-2005-1160: The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain…
PriorityP421medium5.1CVSS 2.0
AVNACHAuNCPIPAP
EPSS
2.72%
84.5th percentile
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
CVSS provenance
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Mozilla Thunderbird vulnerabilities
vendor_ubuntu·2005-08-01
CVE-2005-2353 Mozilla Thunderbird vulnerabilities
Title: Mozilla Thunderbird vulnerabilities
Summary: Mozilla Thunderbird vulnerabilities
Vladimir V. Perepelitsa discovered a bug in Thunderbird's handling of anonymous
functions during regular expression string replacement. A malicious HTML email
could exploit this to capture a random block of client memory. (CAN-2005-0989)
Georgi Guninski discovered that the types of certain XPInstall related
JavaScript objects were not sufficiently validated when they were called. This
could be exploited by malicious HTML email content to crash Thunderbird or even
execute arbitrary code with the privileges of the user. (CAN-2005-1159)
Thunderbird did not properly verify the values of XML DOM nodes. By tricking
the user to perform a common action like clicking on a link or opening the
context menu, a
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities
vendor_ubuntu·2005-07-28
CVE-2004-1156 Ubuntu 4.10 update for Firefox vulnerabilities
Title: Ubuntu 4.10 update for Firefox vulnerabilities
Summary: Ubuntu 4.10 update for Firefox vulnerabilities
USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary
Hedgehog) version of Firefox. The version shipped with Ubuntu 4.10
(Warty Warthog) is also vulnerable to these flaws, so it needs to be
upgraded as well. Please see
http://www.ubuntulinux.org/support/documentation/usn/usn-149-1
for the original advisory.
This update also fixes several older vulnerabilities; Some of them
could be exploited to execute arbitrary code with full user privileges
if the user visited a malicious web site. (MFSA-2005-01 to
MFSA-2005-44; please see the following web site for details:
http://www.mozilla.org/projects/security/known-vulnerabilities.html)
Instructions: In general, a standard sy
Red Hat
security flaw
vendor_redhat·2005-05-18·CVSS 5.1
CVE-2005-1532 [MEDIUM] security flaw
security flaw
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Ubuntu
Mozilla and Firefox vulnerabilities
vendor_ubuntu·2005-05-11
CVE-2005-1155 Mozilla and Firefox vulnerabilities
Title: Mozilla and Firefox vulnerabilities
Summary: Mozilla and Firefox vulnerabilities
When a popup is blocked the user is given the ability to open that
popup through the popup-blocking status bar icon and, in Firefox,
through the information bar. Doron Rosenberg noticed that popups
which are permitted by the user were executed with elevated
privileges, which could be abused to automatically install and execute
arbitrary code with the privileges of the user. (CAN-2005-1153)
It was discovered that the browser did not start with a clean global
JavaScript state for each new website. This allowed a malicious web
page to define a global variable known to be used by a different site,
allowing malicious code to be executed in the context of that site
(for example, sending web mail or automat
Red Hat
security flaw
vendor_redhat·2005-04-15·CVSS 5.1
CVE-2005-1160 [MEDIUM] security flaw
security flaw
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
GHSA
GHSA-ffv2-fj33-mvch: Firefox before 1
ghsa_unreviewed·2022-05-03·CVSS 5.1
CVE-2005-1532 [MEDIUM] GHSA-ffv2-fj33-mvch: Firefox before 1
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
GHSA
GHSA-r5gq-7c27-jhm8: The privileged "chrome" UI code in Firefox before 1
ghsa_unreviewed·2022-05-03
CVE-2005-1160 [MEDIUM] GHSA-r5gq-7c27-jhm8: The privileged "chrome" UI code in Firefox before 1
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-1532 security flaw
bugzilla·2018-08-16·CVSS 5.1
CVE-2005-1532 [MEDIUM] CVE-2005-1532 security flaw
CVE-2005-1532 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Bugzilla
CVE-2005-1160 security flaw
bugzilla·2018-08-16·CVSS 5.1
CVE-2005-1160 [MEDIUM] CVE-2005-1160 security flaw
CVE-2005-1160 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txthttp://secunia.com/advisories/14938http://secunia.com/advisories/14992http://secunia.com/advisories/19823http://www.gentoo.org/security/en/glsa/glsa-200504-18.xmlhttp://www.mozilla.org/security/announce/mfsa2005-41.htmlhttp://www.novell.com/linux/security/advisories/2006_04_25.htmlhttp://www.redhat.com/support/errata/RHSA-2005-383.htmlhttp://www.redhat.com/support/errata/RHSA-2005-384.htmlhttp://www.redhat.com/support/errata/RHSA-2005-386.htmlhttp://www.redhat.com/support/errata/RHSA-2005-601.htmlhttp://www.securityfocus.com/bid/13233http://www.securityfocus.com/bid/15495https://bugzilla.mozilla.org/show_bug.cgi?id=289074https://bugzilla.mozilla.org/show_bug.cgi?id=289083https://bugzilla.mozilla.org/show_bug.cgi?id=289961https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11291ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txthttp://secunia.com/advisories/14938http://secunia.com/advisories/14992http://secunia.com/advisories/19823http://www.gentoo.org/security/en/glsa/glsa-200504-18.xmlhttp://www.mozilla.org/security/announce/mfsa2005-41.htmlhttp://www.novell.com/linux/security/advisories/2006_04_25.htmlhttp://www.redhat.com/support/errata/RHSA-2005-383.htmlhttp://www.redhat.com/support/errata/RHSA-2005-384.htmlhttp://www.redhat.com/support/errata/RHSA-2005-386.htmlhttp://www.redhat.com/support/errata/RHSA-2005-601.htmlhttp://www.securityfocus.com/bid/13233http://www.securityfocus.com/bid/15495https://bugzilla.mozilla.org/show_bug.cgi?id=289074https://bugzilla.mozilla.org/show_bug.cgi?id=289083https://bugzilla.mozilla.org/show_bug.cgi?id=289961https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100017https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11291
2005-05-02
Published