CVE-2005-2267
published 2005-07-13CVE-2005-2267: Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and…
PriorityP428high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.49%
90.5th percentile
Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.15 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r48x-q8w9-w765: Firefox before 1
ghsa_unreviewed·2022-05-01
CVE-2005-2267 [HIGH] GHSA-r48x-q8w9-w765: Firefox before 1
Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.
GHSA
GHSA-9wm7-g493-2j99: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2008-2933 [HIGH] CWE-20 GHSA-9wm7-g493-2j99: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.
Red Hat
Firefox command line URL launches multi-tabs
vendor_redhat·2008-07-15·CVSS 7.5
CVE-2008-2933 [HIGH] Firefox command line URL launches multi-tabs
Firefox command line URL launches multi-tabs
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities
vendor_ubuntu·2005-07-28
CVE-2004-1156 Ubuntu 4.10 update for Firefox vulnerabilities
Title: Ubuntu 4.10 update for Firefox vulnerabilities
Summary: Ubuntu 4.10 update for Firefox vulnerabilities
USN-149-1 fixed some vulnerabilities in the Ubuntu 5.04 (Hoary
Hedgehog) version of Firefox. The version shipped with Ubuntu 4.10
(Warty Warthog) is also vulnerable to these flaws, so it needs to be
upgraded as well. Please see
http://www.ubuntulinux.org/support/documentation/usn/usn-149-1
for the original advisory.
This update also fixes several older vulnerabilities; Some of them
could be exploited to execute arbitrary code with full user privileges
if the user visited a malicious web site. (MFSA-2005-01 to
MFSA-2005-44; please see the following web site for details:
http://www.mozilla.org/projects/security/known-vulnerabilities.html)
Instructions: In general, a standard sy
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2005-07-21
CVE-2005-1937 Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Secunia.com reported that one of the recent security patches in
Firefox reintroduced the frame injection patch that was originally
known as CAN-2004-0718. This allowed a malicious web site to spoof the
contents of other web sites. (CAN-2005-1937)
In several places the browser user interface did not correctly
distinguish between true user events, such as mouse clicks or
keystrokes, and synthetic events genenerated by web content. This
could be exploited by malicious web sites to generate e. g. mouse
clicks that install malicious plugins. Synthetic events are now
prevented from reaching the browser UI entirely. (CAN-2005-2260)
Scripts in XBL controls from web content continued to be run even when
Javascript was disabled. Thi
Red Hat
security flaw
vendor_redhat·2005-07-12·CVSS 7.5
CVE-2005-2267 [HIGH] security flaw
security flaw
Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/16043http://securitytracker.com/id?1014469http://www.ciac.org/ciac/bulletins/p-252.shtmlhttp://www.mozilla.org/security/announce/mfsa2005-53.htmlhttp://www.novell.com/linux/security/advisories/2005_18_sr.htmlhttp://www.novell.com/linux/security/advisories/2005_45_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2005-586.htmlhttp://www.redhat.com/support/errata/RHSA-2005-587.htmlhttp://www.securityfocus.com/bid/14242http://www.vupen.com/english/advisories/2005/1075https://bugzilla.mozilla.org/show_bug.cgi?id=298255https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100006https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11334https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1172http://secunia.com/advisories/16043http://securitytracker.com/id?1014469http://www.ciac.org/ciac/bulletins/p-252.shtmlhttp://www.mozilla.org/security/announce/mfsa2005-53.htmlhttp://www.novell.com/linux/security/advisories/2005_18_sr.htmlhttp://www.novell.com/linux/security/advisories/2005_45_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2005-586.htmlhttp://www.redhat.com/support/errata/RHSA-2005-587.htmlhttp://www.securityfocus.com/bid/14242http://www.vupen.com/english/advisories/2005/1075https://bugzilla.mozilla.org/show_bug.cgi?id=298255https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100006https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1073https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11334https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1172
2005-07-13
Published