19823Third-party advisory
http://secunia.com/advisories/19823 CVE-2005-1532
Mozilla Suite And Firefox - DOM Property Overrides Code Execution
Record summary
CVE-2005-1532 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMozilla Suite And Firefox - DOM Property Overrides Code ExecutionExploitDB exploitby moz_bug_r_a4Not analyzed1 file
References
Showing 12 of 141013964vdb entry
http://securitytracker.com/id?1013964 1013965vdb entry
http://securitytracker.com/id?1013965 mozilla.orgConfirmation
http://www.mozilla.org/security/announce/mfsa2005-44.html SUSE-SA:2006:022Vendor advisory
http://www.novell.com/linux/security/advisories/2006_04_25.html RHSA-2005:434Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-434.html RHSA-2005:435Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-435.html RHSA-2005:601Vendor advisory
http://www.redhat.com/support/errata/RHSA-2005-601.html 13645vdb entry
http://www.securityfocus.com/bid/13645 15495vdb entry
http://www.securityfocus.com/bid/15495 ADV-2005-0530vdb entry
http://www.vupen.com/english/advisories/2005/0530 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1532