CVE-2005-1532
Last modified
CVE-2005-1532 is a vulnerability of currently unknown severity. Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.. EPSS estimates a 9.47% chance of exploitation in the next 30 days.
Description
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 0.8 |
| Mozilla | Firefox | 0.9 |
| Mozilla | Firefox | 0.9.1 |
| Mozilla | Firefox | 0.9.2 |
| Mozilla | Firefox | 0.9.3 |
| Mozilla | Firefox | 0.10 |
| Mozilla | Firefox | 0.10.1 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Mozilla | 1.3 |
| Mozilla | Mozilla | 1.4 |
| Mozilla | Mozilla | 1.4.1 |
| Mozilla | Mozilla | 1.5 |
| Mozilla | Mozilla | 1.5.1 |
| Mozilla | Mozilla | 1.6 |
| Mozilla | Mozilla | 1.7 |
| Mozilla | Mozilla | 1.7.1 |
| Mozilla | Mozilla | 1.7.2 |
| Mozilla | Mozilla | 1.7.3 |
| Mozilla | Mozilla | 1.7.5 |
| Mozilla | Mozilla | 1.7.6 |
| Mozilla | Mozilla | 1.7.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1532?
How severe is CVE-2005-1532?
How do I fix CVE-2005-1532?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-1525SQL injection vulnerability in config_settings.php for Cacti…
- CVE-2005-1526PHP remote file inclusion vulnerability in config_settings.p…
- CVE-2005-1527Eval injection vulnerability in awstats.pl in AWStats 6.4 an…
- CVE-2005-1528Untrusted search path vulnerability in the crttrap command i…
- CVE-2005-1530Sophos Anti-Virus 5.0.1, with "Scan inside archive files" en…
- CVE-2005-1531Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not…
- CVE-2005-1543Multiple stack-based and heap-based buffer overflows in Remo…
- CVE-2005-1544Stack-based buffer overflow in libTIFF before 3.7.2 allows r…
- CVE-2005-1545Integer overflow in the ELF parser in HT Editor before 0.8.0…
- CVE-2005-1546Buffer overflow in the PE parser in HT Editor before 0.8.0 a…
- CVE-2005-1547Heap-based buffer overflow in the demo version of Bakbone Ne…
- CVE-2005-1548SQL injection vulnerability in index.php in Advanced Guestbo…
Are you affected by CVE-2005-1532?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
