Description
The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.
References (19)
Core 19
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2005/dsa-810
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_18_sr.html
Third Party Advisory, US Government Resource third-party-advisory
government-resource
x_refsource_ciac
http://www.ciac.org/ciac/bulletins/p-252.shtml
Issue Tracking vendor-advisory
x_refsource_fedora
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-587.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A742
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/16059
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/16044
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1075
Issue Tracking x_refsource_misc
http://bugzilla.mozilla.org/show_bug.cgi?id=289940
Various Sources x_refsource_misc
http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10132
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1226
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/14242
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-586.html
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/16043
Patch, Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/mfsa2005-45.html
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100013
Scores
EPSS
0.0326
EPSS Percentile
87.0%
Details
Status
published
Products (26)
mozilla/firefox
0.8
mozilla/firefox
0.9 (2 CPE variants)
mozilla/firefox
0.9.1
mozilla/firefox
0.9.2
mozilla/firefox
0.9.3
mozilla/firefox
0.10
mozilla/firefox
0.10.1
mozilla/firefox
1.0
mozilla/firefox
1.0.1
mozilla/firefox
1.0.2
... and 16 more
Published
Jul 13, 2005
Tracked Since
Feb 18, 2026