CVE-2005-2260Insufficient Type Distinction in Mozilla Firefox

Severity
7.5HIGHNVD
EPSS
3.7%
top 12.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13
Latest updateMay 1

Description

The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox12 versions+11
NVDmozilla/mozilla14 versions+13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wm6x-mrp3-f56m: The browser user interface in Firefox before 12022-05-01
CVEList
CVE-2005-2260: The browser user interface in Firefox before 12005-07-13

📋Vendor Advisories

4
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities2005-07-28
Ubuntu
Mozilla vulnerabilities2005-07-27
Ubuntu
Firefox vulnerabilities2005-07-21
Red Hat
security flaw2005-07-12

📐Framework References

1
CWE
Insufficient Type Distinction

💬Community

1
Bugzilla
CVE-2005-2260 security flaw2018-08-16