Vulnerability Name: | CVE-2005-0527 (CCN-19490) | ||||||||||||||||||||
Assigned: | 2005-02-25 | ||||||||||||||||||||
Published: | 2005-02-25 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling." | ||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-0527 Source: BUGTRAQ Type: UNKNOWN 20050225 Firescrolling [Firefox 1.0] Source: CCN Type: BugTraq Mailing List, 2005-02-25 8:10:30 Firescrolling [Firefox 1.0] Source: CCN Type: RHSA-2005-176 firefox security update Source: CCN Type: RHSA-2005-384 Mozilla security update Source: CCN Type: SECTRACK ID: 1013301 Mozilla Firefox XPCOM Access Flaw Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: Exploit 1013301 Source: CCN Type: CIAC INFORMATION BULLETIN P-149 Firefox Security Update Source: CCN Type: GLSA-200503-10 Mozilla Firefox: Various vulnerabilities Source: GENTOO Type: Patch GLSA-200503-10 Source: CCN Type: GLSA-200503-30 Mozilla Suite: Multiple vulnerabilities Source: GENTOO Type: Patch GLSA-200503-30 Source: MISC Type: Exploit http://www.mikx.de/?p=11 Source: CCN Type: Mozilla Firefox Web site Firefox - Rediscover the web Source: CCN Type: Mozilla Firefox Download Web page Download Firefox Source: CONFIRM Type: UNKNOWN http://www.mozilla.org/security/announce/mfsa2005-27.html Source: REDHAT Type: UNKNOWN RHSA-2005:176 Source: REDHAT Type: UNKNOWN RHSA-2005:384 Source: CCN Type: BID-12655 Mozilla Firefox Scrollbar Remote Code Execution Vulnerability Source: XF Type: UNKNOWN mozilla-firefox-xpcom-command-execution(19490) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:100031 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11772 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |