Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2005-05-12T04:00:00
Updated: 2024-08-07T21:51:50.289Z
Reserved: 2005-05-12T00:00:00
Link: CVE-2005-1532
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-05-12T04:00:00.000
Modified: 2024-11-20T23:57:34.097
Link: CVE-2005-1532
Redhat