FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2267

This CVE name corresponds to:

Entered Topic
2005-07-16 firefox & mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2267
Phase Assigned(20050713)

Description

Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/mfsa2005-53.html
MISC https://bugzilla.mozilla.org/show_bug.cgi?id=298255
FEDORA FLSA:160202
REDHAT RHSA-2005:586
REDHAT RHSA-2005:587
SUSE SUSE-SA:2005:045
SUSE SUSE-SR:2005:018
CIAC P-252
BID 14242
OVAL oval:org.mitre.oval:def:11334
VUPEN ADV-2005-1075
OVAL oval:org.mitre.oval:def:100006
OVAL oval:org.mitre.oval:def:1073
OVAL oval:org.mitre.oval:def:1172
SECTRACK 1014469
SECUNIA 16043