CVE-2005-3089: Low severity Mozilla Firefox vulnerability

Published Sep 28, 2005
·
Updated

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

Affected Software

7 affected components
Mozilla Firefox=1.0
Mozilla Firefox=1.0.1
Mozilla Firefox=1.0.2
Mozilla Firefox=1.0.3
Mozilla Firefox=1.0.4
Mozilla Firefox=1.0.5
Mozilla Firefox=1.0.6

Event History

Sep 28, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2005-3089?

CVE-2005-3089 is classified as a denial-of-service vulnerability that can cause Firefox 1.0.6 to crash.

2

How do I fix CVE-2005-3089?

To mitigate CVE-2005-3089, users should upgrade to a later version of Mozilla Firefox beyond 1.0.6, preferably 1.0.7 or newer.

3

Which versions of Firefox are affected by CVE-2005-3089?

CVE-2005-3089 affects Firefox versions 1.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, and 1.0.6.

4

Can CVE-2005-3089 be exploited remotely?

While it's unclear if untrusted parties can trigger CVE-2005-3089, it potentially poses a risk for users running the affected versions.

5

What type of attack is CVE-2005-3089 related to?

CVE-2005-3089 is related to a denial-of-service attack via a Proxy Auto-Config (PAC) script that utilizes an eval statement.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203