CVE
- Id
- 13909
- CVE No.
- CVE-2005-2703
- Status
- Candidate
- Description
- Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
- Phase
- Assigned (20050826)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
101910 | 13909 | CVE-2005-2703 | CONFIRM:http://www.mozilla.org/security/announce/mfsa2005-58.html | View |
101911 | 13909 | CVE-2005-2703 | DEBIAN:DSA-868 | View |
101912 | 13909 | CVE-2005-2703 | URL:http://www.debian.org/security/2005/dsa-868 | View |
101913 | 13909 | CVE-2005-2703 | DEBIAN:DSA-838 | View |
101914 | 13909 | CVE-2005-2703 | URL:http://www.debian.org/security/2005/dsa-838 | View |
101915 | 13909 | CVE-2005-2703 | DEBIAN:DSA-866 | View |
101916 | 13909 | CVE-2005-2703 | URL:http://www.debian.org/security/2005/dsa-866 | View |
101917 | 13909 | CVE-2005-2703 | FEDORA:FLSA-2006:168375 | View |
101918 | 13909 | CVE-2005-2703 | URL:http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00004.html | View |
101919 | 13909 | CVE-2005-2703 | MANDRIVA:MDKSA-2005:169 | View |
101920 | 13909 | CVE-2005-2703 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:169 | View |
101921 | 13909 | CVE-2005-2703 | MANDRIVA:MDKSA-2005:170 | View |
101922 | 13909 | CVE-2005-2703 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:170 | View |
101923 | 13909 | CVE-2005-2703 | MANDRIVA:MDKSA-2005:174 | View |
101924 | 13909 | CVE-2005-2703 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:174 | View |
101925 | 13909 | CVE-2005-2703 | REDHAT:RHSA-2005:785 | View |
101926 | 13909 | CVE-2005-2703 | URL:http://www.redhat.com/support/errata/RHSA-2005-785.html | View |
101927 | 13909 | CVE-2005-2703 | REDHAT:RHSA-2005:789 | View |
101928 | 13909 | CVE-2005-2703 | URL:http://www.redhat.com/support/errata/RHSA-2005-789.html | View |
101929 | 13909 | CVE-2005-2703 | REDHAT:RHSA-2005:791 | View |
101930 | 13909 | CVE-2005-2703 | URL:http://www.redhat.com/support/errata/RHSA-2005-791.html | View |
101931 | 13909 | CVE-2005-2703 | SCO:SCOSA-2005.49 | View |
101932 | 13909 | CVE-2005-2703 | URL:ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt | View |
101933 | 13909 | CVE-2005-2703 | SUSE:SUSE-SA:2005:058 | View |
101934 | 13909 | CVE-2005-2703 | URL:http://www.novell.com/linux/security/advisories/2005_58_mozilla.html | View |
101935 | 13909 | CVE-2005-2703 | UBUNTU:USN-200-1 | View |
101936 | 13909 | CVE-2005-2703 | URL:http://www.ubuntu.com/usn/usn-200-1 | View |
101937 | 13909 | CVE-2005-2703 | BID:14923 | View |
101938 | 13909 | CVE-2005-2703 | URL:http://www.securityfocus.com/bid/14923 | View |
101939 | 13909 | CVE-2005-2703 | BID:15495 | View |
101940 | 13909 | CVE-2005-2703 | URL:http://www.securityfocus.com/bid/15495 | View |
101941 | 13909 | CVE-2005-2703 | OVAL:oval:org.mitre.oval:def:10767 | View |
101942 | 13909 | CVE-2005-2703 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10767 | View |
101943 | 13909 | CVE-2005-2703 | VUPEN:ADV-2005-1824 | View |
101944 | 13909 | CVE-2005-2703 | URL:http://www.vupen.com/english/advisories/2005/1824 | View |
101945 | 13909 | CVE-2005-2703 | OVAL:oval:org.mitre.oval:def:1089 | View |
101946 | 13909 | CVE-2005-2703 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1089 | View |
101947 | 13909 | CVE-2005-2703 | SECTRACK:1014954 | View |
101948 | 13909 | CVE-2005-2703 | URL:http://securitytracker.com/id?1014954 | View |
101949 | 13909 | CVE-2005-2703 | SECUNIA:16911 | View |
101950 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/16911 | View |
101951 | 13909 | CVE-2005-2703 | SECUNIA:16917 | View |
101952 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/16917 | View |
101953 | 13909 | CVE-2005-2703 | SECUNIA:17042 | View |
101954 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17042 | View |
101955 | 13909 | CVE-2005-2703 | SECUNIA:17090 | View |
101956 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17090 | View |
101957 | 13909 | CVE-2005-2703 | SECUNIA:17149 | View |
101958 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17149 | View |
101959 | 13909 | CVE-2005-2703 | SECUNIA:17284 | View |
101960 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17284 | View |
101961 | 13909 | CVE-2005-2703 | SECUNIA:17026 | View |
101962 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17026 | View |
101963 | 13909 | CVE-2005-2703 | SECUNIA:17263 | View |
101964 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17263 | View |
101965 | 13909 | CVE-2005-2703 | SECUNIA:16977 | View |
101966 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/16977 | View |
101967 | 13909 | CVE-2005-2703 | SECUNIA:17014 | View |
101968 | 13909 | CVE-2005-2703 | URL:http://secunia.com/advisories/17014 | View |
101969 | 13909 | CVE-2005-2703 | XF:mozilla-xmlhttprequest-spoofing(22376) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62330 | JVNDB-2005-000532 | Mozilla 製品の JavaScript エンジンにおける整数オーバーフローの脆弱性 | Firefox 1.0.6 以前、Mozilla 1.7.11 以前にはブラウザに実装されている JavaScript エンジンに整数オーバーフローが発生する脆弱性が存在します。 | CVE-2005-2705 | 13909 | 7.5 | http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000532.html | View |