CVE-2005-0752: High severity Mozilla Firefox vulnerability
Published Apr 18, 2005
·Updated
The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
Affected Software
11 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Remediation
Patch Available
Patch Available
Event History
Apr 18, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0752?
CVE-2005-0752 is classified as a critical vulnerability that allows remote code execution.
2
How do I fix CVE-2005-0752?
To resolve CVE-2005-0752, upgrade your Firefox browser to version 1.0.3 or later.
3
What versions of Firefox are affected by CVE-2005-0752?
CVE-2005-0752 affects Firefox versions 0.8 through 1.0.2.
4
What type of attack is associated with CVE-2005-0752?
CVE-2005-0752 is associated with remote code execution via a specially crafted javascript: URL.
5
Can CVE-2005-0752 affect my web application?
Yes, CVE-2005-0752 can affect web applications that utilize the Plugin Finder Service in affected versions of Firefox.