Secunia Logo
 
CVE Reference: CVE-2005-1532
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-1532

Description:
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVE Status:
Candidate

References:

SUSE
  http://www.novell.com/linux/security/advisories/2006_04_25.html

ST
  1013964
  1013965

SCO

SAID
  Secunia Advisory: SA19823

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-434.html
  http://www.redhat.com/support/errata/RHSA-2005-435.html
  http://www.redhat.com/support/errata/RHSA-2005-601.html

OVAL
  http://oval.mitre.org/oval/definitions/data/oval100014.html

CONFIRM
  http://www.mozilla.org/security/announce/mfsa2005-44.html

BID
  15495
  13645


Return to the previous page.