CVE-2005-0402: Low severity Mozilla Firefox vulnerability
Published Mar 24, 2005
·Updated
Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.
Affected Software
11 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 24, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0402?
CVE-2005-0402 has been classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2005-0402?
To fix CVE-2005-0402, update Firefox to version 1.0.2 or later.
3
Which versions of Firefox are affected by CVE-2005-0402?
CVE-2005-0402 affects Firefox versions prior to 1.0.2, including versions 0.8, 0.9, and 1.0.
4
What kind of attack is facilitated by CVE-2005-0402?
CVE-2005-0402 enables attackers to execute arbitrary code through JavaScript injection via a tricked sidebar panel.
5
Is there any workaround for CVE-2005-0402 until I can update my browser?
There is no known effective workaround for CVE-2005-0402 other than upgrading Firefox to a secure version.