Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.mozilla.org/security/announce/mfsa2005-44.html | |
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2005-435.html | vendor advisory |
http://secunia.com/advisories/19823 | third party advisory |
http://securitytracker.com/id?1013964 | vdb entry |
http://www.securityfocus.com/bid/15495 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100014 | signature vdb entry |
http://www.redhat.com/support/errata/RHSA-2005-601.html | vendor advisory |
http://securitytracker.com/id?1013965 | vdb entry |
http://www.securityfocus.com/bid/13645 | vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10791 | signature vdb entry |
http://www.vupen.com/english/advisories/2005/0530 | vdb entry |
http://www.novell.com/linux/security/advisories/2006_04_25.html | vendor advisory |
http://www.redhat.com/support/errata/RHSA-2005-434.html | vendor advisory |