CVE-2005-2703Code Injection in Mozilla Firefox

CWE-94Code Injection6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
4.7%
top 10.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 23
Latest updateMay 3

Description

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox1.0.6+6
NVDmozilla/mozilla_suite1.7.11+4

🔴Vulnerability Details

2
GHSA
GHSA-g9fw-v33p-xrq5: Firefox before 12022-05-03
CVEList
CVE-2005-2703: Firefox before 12005-09-23

📋Vendor Advisories

2
Ubuntu
Thunderbird vulnerabilities2005-10-11
Red Hat
security flaw2005-09-22

💬Community

1
Bugzilla
CVE-2005-2703 security flaw2018-08-16
CVE-2005-2703 — Code Injection in Mozilla Firefox | cvebase