FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2706

This CVE name corresponds to:

Entered Topic
2005-09-23 firefox & mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2706
Phase Assigned(20050826)

Description

Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/mfsa2005-58.html
DEBIAN DSA-868
DEBIAN DSA-838
DEBIAN DSA-866
FEDORA FLSA-2006:168375
MANDRIVA MDKSA-2005:169
MANDRIVA MDKSA-2005:170
MANDRIVA MDKSA-2005:174
REDHAT RHSA-2005:785
REDHAT RHSA-2005:789
REDHAT RHSA-2005:791
SCO SCOSA-2005.49
SUSE SUSE-SA:2005:058
SUSE SUSE-SA:2006:022
SUSE SUSE-SA:2006:004
UBUNTU USN-200-1
BID 14920
BID 15495
OVAL oval:org.mitre.oval:def:11317
VUPEN ADV-2005-1824
OSVDB 19648
OVAL oval:org.mitre.oval:def:1443
SECTRACK 1014954
SECUNIA 16911
SECUNIA 16917
SECUNIA 17042
SECUNIA 17090
SECUNIA 17149
SECUNIA 17284
SECUNIA 17026
SECUNIA 17263
SECUNIA 16977
SECUNIA 17014
SECUNIA 19823
XF mozilla-about-execute-code(22378)