CVE-2005-2270

Firefox <1.0.5 - Mozilla <1.7.9 - RCE

Title source: llm
STIX 2.1

Description

Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

References (25)

Core 25
Core References
Exploit, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=294795
Patch, Vendor Advisory x_refsource_confirm
http://www.mozilla.org/security/announce/mfsa2005-56.html
Third Party Advisory, US Government Resource third-party-advisory government-resource x_refsource_ciac
http://www.ciac.org/ciac/bulletins/p-252.shtml
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2005/dsa-810
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_18_sr.html
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11751
Exploit, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=295011
Exploit, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=294799
Issue Tracking vendor-advisory x_refsource_fedora
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A550
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19823
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A817
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-587.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16059
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1075
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-601.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014470
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/652366
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14242
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2005-586.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16043
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2006_04_25.html
Exploit, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=296397
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100003

Scores

EPSS 0.0596
EPSS Percentile 92.5%

Details

Status published
Products (26)
mozilla/firefox 0.8
mozilla/firefox 0.9 (2 CPE variants)
mozilla/firefox 0.9.1
mozilla/firefox 0.9.2
mozilla/firefox 0.9.3
mozilla/firefox 0.10
mozilla/firefox 0.10.1
mozilla/firefox 1.0
mozilla/firefox 1.0.1
mozilla/firefox 1.0.2
... and 16 more
Published Jul 13, 2005
Tracked Since Feb 18, 2026