Mozilla Firefox < 1.0.2 Multiple Vulnerabilities

medium Nessus Network Monitor Plugin ID 2704

Synopsis

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Description

The remote host is using Firefox. The remote version of this software contains multiple security flaws that can be exploited by a malicious website. An attacker exploiting one of these flaws would need to be able to either convince a remote user to visit a malicious website or convince the remote user to open an HTML email and save an attachment.
In addition, this version is vulnerable to a remote flaw that could result in arbitrary code execution. Specifically, if a malicious web page is bookmarked as a sidebar panel, the malicious page may open and inject code into privileged pages. An attacker exploiting this flaw would need to be able to convince a user to both visit and bookmark their malicious web page.

Solution

Upgrade to version 1.0.2 or higher.

See Also

http://www.mozilla.org

Plugin Details

Severity: Medium

ID: 2704

Family: Web Clients

Published: 3/14/2005

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Reference Information

CVE: CVE-2005-0401, CVE-2005-0402, CVE-2005-4809

BID: 12885, 12798, 12672, 12884