[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2005-2269Date: (C)2005-07-13   (M)2024-03-27


Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-14242
SECUNIA-16043
SECUNIA-16044
SECUNIA-16059
SECUNIA-19823
ADV-2005-1075
DSA-810
FLSA:160202
P-252
RHSA-2005:586
RHSA-2005:587
RHSA-2005:601
SUSE-SA:2005:045
SUSE-SA:2006:004
SUSE-SR:2005:018
http://www.mozilla.org/security/announce/mfsa2005-55.html
http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
https://bugzilla.mozilla.org/show_bug.cgi?id=298892
oval:org.mitre.oval:def:100004
oval:org.mitre.oval:def:100005
oval:org.mitre.oval:def:100011
oval:org.mitre.oval:def:1258
oval:org.mitre.oval:def:729
oval:org.mitre.oval:def:9777

CPE    38
cpe:/a:mozilla:mozilla:1.4
cpe:/a:mozilla:mozilla:1.3
cpe:/a:mozilla:mozilla:1.6
cpe:/a:mozilla:mozilla:1.5
...
OVAL    1
oval:org.mitre.oval:def:100004

© SecPod Technologies