Oval Definition:oval:org.mitre.oval:def:100002
Revision Date:2007-03-21Version:3
Title:IFRAME in Firefox and Mozilla Permits Execution of Arbitrary Javascript in Other Domains
Description:Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2005-1476
Platform(s):Microsoft Windows 2000
Microsoft Windows NT
Microsoft Windows Server 2003
Microsoft Windows XP
Product(s):mozilla
Definition Synopsis
  • Firefox <= 1.0.3 or Mozilla Suite <= 1.7.7 is installed
  • Firefox version 1.0.3 or earlier is installed
  • OR Mozilla Suite version 1.7.7 or earlier is installed
  • BACK