Nine vulnerabilities were identified in Mozilla Suite and Firefox, which may be exploited by malicious Websites to execute arbitrary commands or conduct Cross Site Scripting attacks.
- moz_bug_r_a4 reported several exploits giving an attacker the ability to install malicious code or steal data, requiring only that the user do commonplace actions like click on a link or open the context menu. The common cause in each case was privileged UI code ("chrome") being overly trusting of DOM nodes from the content window [...]
Affected Products
Mozilla Firefox version 1.0.2 and prior
Mozilla Suite version 1.7.6 and prior
Netscape version 7.2 and prior
Credits
Vulnerabilities reported by moz_bug_r_a4, Georgi Guninski, Kohei Yoshino, Michael Krax, Doron Rosenberg, Omar Khan, Azafran Vladimir V. Perepelitsa
ChangeLog
2005-04-16 : Initial release
2005-04-21 : Netscape Affected
2005-05-20 : Updated Solution
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.