Lucene search

K
cveRedhatCVE-2005-1157
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-1157

2005-05-0204:00:00
redhat
web.nvd.nist.gov
38
cve-2005-1157
firefox
mozilla suite
netscape
search plugin
remote attack
malicious script.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

High

EPSS

0.019

Percentile

88.5%

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka “Firesearching 2.”

Affected configurations

Nvd
Node
mozillafirefoxMatch0.8
OR
mozillafirefoxMatch0.9
OR
mozillafirefoxMatch0.9rc
OR
mozillafirefoxMatch0.9.1
OR
mozillafirefoxMatch0.9.2
OR
mozillafirefoxMatch0.9.3
OR
mozillafirefoxMatch0.10
OR
mozillafirefoxMatch0.10.1
OR
mozillafirefoxMatch1.0
OR
mozillafirefoxMatch1.0.1
OR
mozillafirefoxMatch1.0.2
OR
mozillamozillaMatch1.3
OR
mozillamozillaMatch1.4
OR
mozillamozillaMatch1.4alpha
OR
mozillamozillaMatch1.4.1
OR
mozillamozillaMatch1.5
OR
mozillamozillaMatch1.5alpha
OR
mozillamozillaMatch1.5rc1
OR
mozillamozillaMatch1.5rc2
OR
mozillamozillaMatch1.5.1
OR
mozillamozillaMatch1.6
OR
mozillamozillaMatch1.6alpha
OR
mozillamozillaMatch1.6beta
OR
mozillamozillaMatch1.7
OR
mozillamozillaMatch1.7alpha
OR
mozillamozillaMatch1.7beta
OR
mozillamozillaMatch1.7rc1
OR
mozillamozillaMatch1.7rc2
OR
mozillamozillaMatch1.7rc3
OR
mozillamozillaMatch1.7.1
OR
mozillamozillaMatch1.7.2
OR
mozillamozillaMatch1.7.3
OR
mozillamozillaMatch1.7.5
OR
mozillamozillaMatch1.7.6
OR
netscapenavigatorMatch7.2
VendorProductVersionCPE
mozillamozilla1.7cpe:/a:mozilla:mozilla:1.7:beta::
mozillamozilla1.7.5cpe:/a:mozilla:mozilla:1.7.5:::
mozillafirefox0.8cpe:/a:mozilla:firefox:0.8:::
mozillamozilla1.7cpe:/a:mozilla:mozilla:1.7:alpha::
mozillafirefox1.0.2cpe:/a:mozilla:firefox:1.0.2:::
mozillamozilla1.4cpe:/a:mozilla:mozilla:1.4:alpha::
netscapenavigator7.2cpe:/a:netscape:navigator:7.2:::
mozillamozilla1.7.1cpe:/a:mozilla:mozilla:1.7.1:::
mozillamozilla1.5.1cpe:/a:mozilla:mozilla:1.5.1:::
mozillamozilla1.4cpe:/a:mozilla:mozilla:1.4:::
Rows per page:
1-10 of 351

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.4

Confidence

High

EPSS

0.019

Percentile

88.5%