CVE-2005-2706: Medium severity Mozilla Firefox vulnerability
Published Sep 23, 2005
·Updated
Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.
Affected Software
12 affected components
Mozilla Firefox<=1.0.6
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Mozilla Firefox=1.0.3
Mozilla Firefox=1.0.4
Mozilla Firefox=1.0.5
Mozilla Mozilla Suite<=1.7.11
Mozilla Mozilla Suite=1.7.6
Mozilla Mozilla Suite=1.7.7
Mozilla Mozilla Suite=1.7.8
Mozilla Mozilla Suite=1.7.10
Event History
Sep 23, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2706?
CVE-2005-2706 has a critical severity due to its potential to allow remote code execution with elevated privileges.
2
How do I fix CVE-2005-2706?
To fix CVE-2005-2706, upgrade Firefox to version 1.0.7 or later, or Mozilla Suite to version 1.7.12 or later.
3
What are the versions affected by CVE-2005-2706?
CVE-2005-2706 affects Firefox versions up to 1.0.6 and Mozilla Suite versions up to 1.7.11.
4
What type of attack does CVE-2005-2706 involve?
CVE-2005-2706 involves a remote code execution attack allowing execution of Javascript with chrome privileges.
5
Is there a workaround for CVE-2005-2706 until I can update?
No specific workaround is recommended for CVE-2005-2706; updating to a patched version is the best solution.