CVE-2005-1157: High severity Mozilla Firefox vulnerability
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1157?
CVE-2005-1157 has a medium severity level, indicating potential for compromise via manipulated search plugins.
How do I fix CVE-2005-1157?
To fix CVE-2005-1157, update to the latest version of Firefox or Mozilla Suite where this vulnerability has been addressed.
What types of software are affected by CVE-2005-1157?
CVE-2005-1157 affects multiple versions of Firefox, Mozilla Suite, and Netscape Browser, particularly those released before specific patches.
Can CVE-2005-1157 allow unauthorized access?
Yes, CVE-2005-1157 can allow remote attackers to replace search plugins, potentially allowing unauthorized actions through malicious plugins.
How can I determine if I'm using a vulnerable version related to CVE-2005-1157?
Check your browser's version against the known affected versions, including Firefox versions before 1.0.3 and Mozilla Suite versions prior to 1.7.7 for CVE-2005-1157.