CVE Vulnerabilities

CVE-2005-0231

Published: Feb 07, 2005 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka firetabbing.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 1.0 (including) 1.0 (including)
Red Hat Enterprise Linux 2.1 RedHat galeon *
Red Hat Enterprise Linux 2.1 RedHat mozilla *
Red Hat Enterprise Linux 3 RedHat mozilla *
Red Hat Enterprise Linux 4 RedHat firefox-0:1.0.1-1.4.3 *
Firefox Ubuntu dapper *
Firefox Ubuntu devel *
Firefox Ubuntu edgy *
Firefox Ubuntu feisty *
Firefox-granparadiso Ubuntu devel *
Lightning-sunbird Ubuntu devel *
Midbrowser Ubuntu devel *

References