CVE-2005-1477
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 15%
from disclosure to weapon0 days
Published on NVDMay 9
1st PoCMay 7
exploitation probability
15%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/986⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txthttp://greyhatsecurity.org/firefox.htmhttp://greyhatsecurity.org/vulntests/ffrc.htmhttp://marc.info/?l=full-disclosure&m=111553138007647&w=2http://marc.info/?l=full-disclosure&m=111556301530553&w=2https://bugzilla.mozilla.org/show_bug.cgi?id=292691https://bugzilla.mozilla.org/show_bug.cgi?id=293302http://secunia.com/advisories/15292http://securitytracker.com/id?1013913https://exchange.xforce.ibmcloud.com/vulnerabilities/20443https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100001https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9231