First published: Sat Jan 29 2005(Updated: )
Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =0.8 | |
Mozilla Firefox | =0.9.1 | |
Mozilla Firefox | =0.10.1 | |
Mozilla Firefox | =0.9 | |
Mozilla Firefox | =1.0 | |
Mozilla Firefox | =0.9.3 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Firefox | =0.9-rc | |
Mozilla Firefox | =0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0150 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2005-0150, upgrade to Mozilla Firefox version 1.0 or later.
CVE-2005-0150 affects Firefox versions 0.8, 0.9, and 1.0.
CVE-2005-0150 can be exploited by an attacker to execute arbitrary JavaScript code in the context of another page.
While CVE-2005-0150 is an older vulnerability, users of outdated Firefox versions may still be at risk.