Description
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").
Published: 2005-07-13
Score: 7.5 High
EPSS: 7.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2005-2270 Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").
Ubuntu USN Ubuntu USN USN-149-1 Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-149-3 Ubuntu 4.10 update for Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-155-1 Mozilla vulnerabilities
Ubuntu USN Ubuntu USN USN-157-1 Mozilla Thunderbird vulnerabilities
References
Link Providers
http://secunia.com/advisories/16043 cve-icon cve-icon
http://secunia.com/advisories/16044 cve-icon cve-icon
http://secunia.com/advisories/16059 cve-icon cve-icon
http://secunia.com/advisories/19823 cve-icon cve-icon
http://www.ciac.org/ciac/bulletins/p-252.shtml cve-icon cve-icon
http://www.debian.org/security/2005/dsa-810 cve-icon cve-icon
http://www.mozilla.org/security/announce/mfsa2005-55.html cve-icon cve-icon
http://www.networksecurity.fi/advisories/netscape-multiple-issues.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2005_18_sr.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2005_45_mozilla.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_04_25.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2005-586.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2005-587.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2005-601.html cve-icon cve-icon
http://www.securityfocus.com/bid/14242 cve-icon cve-icon
http://www.vupen.com/english/advisories/2005/1075 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=298892 cve-icon cve-icon
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2005-2269 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100004 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100005 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100011 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1258 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A729 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9777 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2005-2269 cve-icon
History

No history.

Subscriptions

Mozilla Firefox Mozilla
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T22:22:47.768Z

Reserved: 2005-07-13T00:00:00.000Z

Link: CVE-2005-2269

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-07-13T04:00:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2005-2269

cve-icon Redhat

Severity : Moderate

Publid Date: 2005-07-12T00:00:00Z

Links: CVE-2005-2269 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses