CVE-2005-1937Mozilla Firefox vulnerability

7 documents5 sources
Severity
2.6LOWNVD
EPSS
0.8%
top 25.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 14
Latest updateMay 1

Description

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

CVSS vector

AV:N/AC:H/C:N/I:P/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox1.0.3
NVDmozilla/mozilla1.7.7

🔴Vulnerability Details

1
GHSA
GHSA-ffxc-32xj-v3rp: A regression error in Firefox 12022-05-01

📋Vendor Advisories

4
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities2005-07-28
Ubuntu
Mozilla vulnerabilities2005-07-27
Ubuntu
Firefox vulnerabilities2005-07-21
Red Hat
security flaw2005-06-06

💬Community

1
Bugzilla
CVE-2005-1937 security flaw2018-08-16