Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2005-2270 | Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing"). |
Ubuntu USN |
USN-149-1 | Firefox vulnerabilities |
Ubuntu USN |
USN-149-3 | Ubuntu 4.10 update for Firefox vulnerabilities |
Ubuntu USN |
USN-155-1 | Mozilla vulnerabilities |
Ubuntu USN |
USN-157-1 | Mozilla Thunderbird vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T22:22:47.768Z
Reserved: 2005-07-13T00:00:00
Link: CVE-2005-2269
No data.
Status : Deferred
Published: 2005-07-13T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-2269
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN