CVE-2005-1532
- EPSS 17.43%
- Veröffentlicht 12.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a va...
CVE-2005-1576
- EPSS 0.49%
- Veröffentlicht 12.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real...
CVE-2005-1476
- EPSS 49.76%
- Veröffentlicht 09.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.
CVE-2005-1477
- EPSS 41.65%
- Veröffentlicht 09.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when ...
CVE-2005-0141
- EPSS 0.75%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.
CVE-2005-0142
- EPSS 0.06%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. conten...
CVE-2005-0144
- EPSS 0.64%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
- EPSS 0.77%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.
CVE-2005-0147
- EPSS 1.13%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.
CVE-2005-0230
- EPSS 2.21%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execu...