CVE-2005-1531: High severity Mozilla Firefox vulnerability
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1531?
CVE-2005-1531 has been classified as a high severity vulnerability due to its potential for remote script execution.
How do I fix CVE-2005-1531?
To fix CVE-2005-1531, users should upgrade to a version of Firefox later than 1.0.4 or Mozilla Suite later than 1.7.8.
What types of attacks are possible with CVE-2005-1531?
CVE-2005-1531 allows attackers to execute arbitrary scripts via specially crafted javascript: URLs.
Which software versions are affected by CVE-2005-1531?
A variety of Firefox versions up to 1.0.3 and several Mozilla Suite versions up to 1.7.8 are affected by CVE-2005-1531.
Is CVE-2005-1531 still a concern today?
While CVE-2005-1531 is an older vulnerability, systems running outdated versions of Firefox or Mozilla may still be at risk.