CVE-2005-1477 is a critical vulnerability in Firefox 1.0.3 that allows remote websites on the browser's whitelist (e.g., update.mozilla.org) to execute arbitrary JavaScript with chrome privileges. This, when combined with other vulnerabilities like CVE-2005-1476, can lead to arbitrary code execution on the user's system. The attack vector is network-based with high attack complexity, and it carries a CVSS score of 5.1, indicating potential for partial confidentiality, integrity, and availability impact. While not currently on CISA's KEV catalog or actively exploited, public exploit code exists (EDB-986), and its FAUCET Risk Score of 97/100 highlights its significant danger despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.