CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12359 | CVE-2005-1153 | Candidate | Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option. | Assigned (20050418) | None (candidate not yet proposed) | View | |
12360 | CVE-2005-1154 | Candidate | Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution." | Assigned (20050418) | None (candidate not yet proposed) | View | |
12361 | CVE-2005-1155 | Candidate | The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking." | Assigned (20050418) | None (candidate not yet proposed) | View | |
12362 | CVE-2005-1156 | Candidate | Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1." | Assigned (20050418) | None (candidate not yet proposed) | View | |
12363 | CVE-2005-1157 | Candidate | Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2." | Assigned (20050418) | None (candidate not yet proposed) | View |
Page 19545 of 20943, showing 5 records out of 104715 total, starting on record 97721, ending on 97725