CVE-2005-2262 EXPLOIT
5.1
MEDIUM · CVSS 2.0 · EPSS 6.5% (pctl 94)
Patch early
A public exploit exists.
Description
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."
Scoring
| CVSS | 5.1 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
| EPSS | 6.55% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-07-13 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| mozilla | firefox |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mozilla Firefox 1.0.4 - 'Set As Wallpaper' Code Execution | 2005-07-13 |
References
- http://secunia.com/advisories/16043
- http://secunia.com/advisories/16044
- http://www.ciac.org/ciac/bulletins/p-252.shtml
- http://www.mikx.de/firewalling/
- http://www.mozilla.org/security/announce/mfsa2005-47.html
- http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
- http://www.novell.com/linux/security/advisories/2005_18_sr.html
- http://www.novell.com/linux/security/advisories/2005_45_mozilla.html
- http://www.redhat.com/support/errata/RHSA-2005-586.html
- http://www.securiteam.com/securitynews/5ZP0E0UGAK.html
- http://www.securityfocus.com/bid/14242
- http://www.vupen.com/english/advisories/2005/1075
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100011
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11097
- http://secunia.com/advisories/16043
- http://secunia.com/advisories/16044
- http://www.ciac.org/ciac/bulletins/p-252.shtml
- http://www.mikx.de/firewalling/
- http://www.mozilla.org/security/announce/mfsa2005-47.html
- http://www.networksecurity.fi/advisories/netscape-multiple-issues.html
→ the Explorer · watch your stack · NVD