Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-1476Mozilla Firefox vulnerability

9 documents5 sources
Severity
5.1MEDIUMNVD
EPSS
49.8%
top 2.18%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMay 9
Latest updateMay 3

Description

Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 4.9 | Impact: 6.4

Affected Packages1 packages

NVDmozilla/firefox1.0.3+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x2x8-qmfc-8j2r: The install function in Firefox 12022-05-03
GHSA
GHSA-364v-59j7-j8j2: Firefox 12022-05-03

💥Exploits & PoCs

1
Exploit-DB
Mozilla Firefox 1.0.3 - Install Method Arbitrary Code Execution2005-05-07

📋Vendor Advisories

2
Red Hat
security flaw2005-05-08
Red Hat
security flaw2005-05-08

💬Community

2
Bugzilla
CVE-2005-1477 security flaw2018-08-16
Bugzilla
CVE-2005-1476 security flaw2018-08-16