First published: Tue Sep 14 2004(Updated: )
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Mozilla | =1.4.2 | |
Mozilla Firefox | =0.8 | |
Conectiva Linux | =9.0 | |
Mozilla Mozilla | =1.0.1 | |
Mozilla Mozilla | =1.2.1 | |
Mozilla Mozilla | =1.0-rc1 | |
Mozilla Mozilla | =1.2-alpha | |
Mozilla Mozilla | =1.7 | |
Mozilla Mozilla | =1.1-beta | |
Mozilla Firefox | =0.9.1 | |
Mozilla Mozilla | =1.0-rc2 | |
Netscape Navigator | =7.1 | |
Mozilla Firefox | =0.9 | |
Netscape Navigator | =7.2 | |
Mozilla Mozilla | =1.4.1 | |
Mozilla Mozilla | =1.4-beta | |
Mozilla Mozilla | =1.2 | |
Mozilla Mozilla | =1.3 | |
Mozilla Mozilla | =1.2-beta | |
Netscape Navigator | =7.0 | |
Mozilla Mozilla | =1.0 | |
Mozilla Mozilla | =1.4 | |
Mozilla Mozilla | =1.5 | |
Mozilla Mozilla | =1.7.1 | |
Netscape Navigator | =7.0.2 | |
Mozilla Firefox | =0.9.3 | |
Mozilla Mozilla | =1.4-alpha | |
Mozilla Mozilla | =1.1 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Mozilla | =1.1-alpha | |
Conectiva Linux | =10.0 | |
Mozilla Mozilla | =1.7.2 | |
Mozilla Firefox | =0.9-rc | |
Mozilla Mozilla | =1.0.2 | |
Mozilla Mozilla | =1.7-rc3 | |
Mozilla Mozilla | =1.3.1 | |
Mozilla Mozilla | =1.6 | |
SUSE Linux | =9.0 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Linux | =7.3 | |
redhat enterprise Linux desktop | =3.0 | |
SUSE Linux | =9.0 | |
Red Hat Linux Advanced Workstation | =2.1 | |
SUSE Linux | =8.2 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
SUSE Linux | =8 | |
SUSE Linux | =1.0 | |
Red Hat Enterprise Linux | =2.1 | |
SUSE Linux | =9.0 | |
Red Hat Fedora Core | =core_1.0 | |
Red Hat Linux | =7.3 | |
Red Hat Linux | =9.0 | |
Red Hat Linux Advanced Workstation | =2.1 | |
SUSE Linux | =9.1 | |
Red Hat Enterprise Linux | =3.0 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Linux | =7.3 | |
Red Hat Enterprise Linux | =2.1 | |
SUSE Linux | =8.1 | |
Red Hat Enterprise Linux | =2.1 | |
Red Hat Enterprise Linux | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0905 is categorized as a high-severity vulnerability due to its potential for cross-domain scripting and the execution of arbitrary code.
To mitigate the effects of CVE-2004-0905, users should update to the latest versions of Mozilla Firefox, Mozilla, or Thunderbird that do not have this vulnerability.
CVE-2004-0905 affects various versions of Mozilla Firefox, Mozilla, and Thunderbird prior to specific updates.
CVE-2004-0905 involves cross-domain scripting, where attackers can manipulate browser behavior by leveraging drag and drop techniques.
Yes, CVE-2004-0905 can be exploited by remote attackers who convince users to perform specific actions that trigger the vulnerability.