CVE-2004-0905: Medium severity mozilla mozilla vulnerability
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0905?
CVE-2004-0905 is categorized as a high-severity vulnerability due to its potential for cross-domain scripting and the execution of arbitrary code.
How do I fix CVE-2004-0905?
To mitigate the effects of CVE-2004-0905, users should update to the latest versions of Mozilla Firefox, Mozilla, or Thunderbird that do not have this vulnerability.
What applications are affected by CVE-2004-0905?
CVE-2004-0905 affects various versions of Mozilla Firefox, Mozilla, and Thunderbird prior to specific updates.
What type of attack does CVE-2004-0905 involve?
CVE-2004-0905 involves cross-domain scripting, where attackers can manipulate browser behavior by leveraging drag and drop techniques.
Can CVE-2004-0905 be exploited remotely?
Yes, CVE-2004-0905 can be exploited by remote attackers who convince users to perform specific actions that trigger the vulnerability.