CVE-2005-1154: High severity Mozilla Firefox vulnerability
Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1154?
CVE-2005-1154 is classified as a moderate severity vulnerability.
How do I fix CVE-2005-1154?
To fix CVE-2005-1154, update to Firefox version 1.0.3 or later, or Mozilla Suite version 1.7.7 or later.
What types of software are affected by CVE-2005-1154?
CVE-2005-1154 affects multiple versions of Firefox and the Mozilla Suite prior to specified versions.
What is the nature of the vulnerability in CVE-2005-1154?
CVE-2005-1154 allows remote attackers to execute arbitrary scripts in other domains through cross-site scripting.
How does CVE-2005-1154 exploit work?
The exploit in CVE-2005-1154 takes advantage of global scope pollution, affecting the execution of setter functions.