Vulnerability Name: | CVE-2005-2262 (CCN-21405) | ||||||||||||||||||||
Assigned: | 2005-07-12 | ||||||||||||||||||||
Published: | 2005-07-12 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling." | ||||||||||||||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.1 Medium (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-2262 Source: CCN Type: RHSA-2005-586 firefox security update Source: CCN Type: SA16043 Firefox Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 16043 Source: CCN Type: SA16044 Netscape Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 16044 Source: CCN Type: CIAC INFORMATION BULLETIN P-251 Mozilla Security Updates Source: CCN Type: CIAC INFORMATION BULLETIN P-252 Firefox Security Updates Source: CIAC Type: UNKNOWN P-252 Source: DEBIAN Type: DSA-779 mozilla-firefox -- several vulnerabilities Source: MISC Type: UNKNOWN http://www.mikx.de/firewalling/ Source: CCN Type: Mozilla Firefox Download Web page Firefox - Rediscover the web Source: CCN Type: MFSA 2005-47 Code execution via "Set as Wallpaper" Source: CONFIRM Type: UNKNOWN http://www.mozilla.org/security/announce/mfsa2005-47.html Source: MISC Type: UNKNOWN http://www.networksecurity.fi/advisories/netscape-multiple-issues.html Source: SUSE Type: UNKNOWN SUSE-SR:2005:018 Source: SUSE Type: UNKNOWN SUSE-SA:2005:045 Source: REDHAT Type: UNKNOWN RHSA-2005:586 Source: MISC Type: UNKNOWN http://www.securiteam.com/securitynews/5ZP0E0UGAK.html Source: BID Type: UNKNOWN 14242 Source: CCN Type: BID-14242 Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities Source: CCN Type: USN-149-3 Ubuntu 4.10 update for Firefox vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2005-1075 Source: XF Type: UNKNOWN firefox-wallpaper-code-execution(21405) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:100011 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11097 Source: SUSE Type: SUSE-SA:2005:045 mozilla MozillaFirefox epiphany galeon: information leak | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |