CVE Vulnerabilities

CVE-2005-0231

Published: Feb 07, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka firetabbing.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla1.0 (including)1.0 (including)
Red Hat Enterprise Linux 4RedHatfirefox-0:1.0.1-1.4.3*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*
Firefox-granparadisoUbuntudevel*
Lightning-sunbirdUbuntudevel*
MidbrowserUbuntudevel*

References