peter bassill · operator
$ cve CVE-2005-1477 JSON

CVE-2005-1477 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 15.2% (pctl 97)

Patch early

A public exploit exists.

Description

The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS15.24% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-09
Last modified2026-06-16

Affected (1)

VendorProduct
mozillafirefox

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD