CVE-2005-1937
Last modified
CVE-2005-1937 is a vulnerability of currently unknown severity. A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.
Description
A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Mozilla | 1.7.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1937?
How severe is CVE-2005-1937?
How do I fix CVE-2005-1937?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-1931GoodTech SMTP Server 5.14 allows remote attackers to cause a…
- CVE-2005-1932Lpanel 1.59 and earlier, and other versions before 1.597, al…
- CVE-2005-1933Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to e…
- CVE-2005-1934Gaim before 1.3.1 allows remote attackers to cause a denial …
- CVE-2005-1935Heap-based buffer overflow in the BERDecBitString function i…
- CVE-2005-1936Unknown vulnerability in the web server for the ESS/ Network…
- CVE-2005-1938Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2005-1939Directory traversal vulnerability in Ipswitch WhatsUp Small …
- CVE-2005-1941SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, …7.8
- CVE-2005-1942Cisco switches that support 802.1x security allow remote att…
- CVE-2005-1943Multiple SQL injection vulnerabilities in Loki download mana…
- CVE-2005-1944xmysqladmin 1.0 and earlier allows local users to delete arb…
Are you affected by CVE-2005-1937?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
