CVE-2005-2264: High severity Mozilla Firefox vulnerability
Published Jul 13, 2005
·Updated
Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the search target, then injecting script into other pages via a data: URL.
Affected Software
13 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Mozilla Firefox=1.0.3
Mozilla Firefox=1.0.4
Remediation
Patch Available
Event History
Jul 13, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2264?
CVE-2005-2264 is classified as a medium severity vulnerability.
2
How do I fix CVE-2005-2264?
To fix CVE-2005-2264, upgrade to Firefox version 1.0.5 or later.
3
What kind of information can be stolen through CVE-2005-2264?
CVE-2005-2264 allows remote attackers to steal sensitive information by injecting scripts into other pages.
4
Which versions of Firefox are affected by CVE-2005-2264?
CVE-2005-2264 affects multiple versions of Firefox prior to 1.0.5, including versions 0.8, 0.9, and 1.0.x.
5
Is any user action required to exploit CVE-2005-2264?
Yes, a user must click on a malicious link that is opened in the Firefox sidebar for the exploit to be effective.