Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T21:51:50.289Z
Reserved: 2005-05-12T00:00:00
Link: CVE-2005-1532

No data.

Status : Deferred
Published: 2005-05-12T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-1532
