Lucene search

K
cve[email protected]CVE-2005-2262
HistoryJul 13, 2005 - 4:00 a.m.

CVE-2005-2262

2005-07-1304:00:00
web.nvd.nist.gov
45
firefox
netscape
remote code execution
image url
context menu
cve-2005-2262

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.571

Percentile

97.7%

Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the “Set As Wallpaper” (in Firefox) or “Set as Background” (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka “Firewalling.”

Affected configurations

NVD
Node
mozillafirefoxMatch1.0.3
OR
mozillafirefoxMatch1.0.4
VendorProductVersionCPE
mozillafirefox1.0.3cpe:/a:mozilla:firefox:1.0.3:::
mozillafirefox1.0.4cpe:/a:mozilla:firefox:1.0.4:::

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.571

Percentile

97.7%