CVE-2005-2703
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling…
Does this matter?
Lower severity and a low EPSS score (1.79%). Track it; it rarely justifies an emergency change on its own.
Description
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- mozilla/firefox · mozilla/mozilla suite
- Source
- secalert@redhat.com
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
- http://secunia.com/advisories/16911Vendor Advisory
- http://secunia.com/advisories/16917Vendor Advisory
- http://secunia.com/advisories/16977Vendor Advisory
- http://secunia.com/advisories/17014Vendor Advisory
- http://secunia.com/advisories/17026Vendor Advisory
- http://secunia.com/advisories/17042Vendor Advisory
- http://secunia.com/advisories/17090Vendor Advisory
- http://secunia.com/advisories/17149Vendor Advisory
- http://secunia.com/advisories/17263Vendor Advisory
- http://secunia.com/advisories/17284Vendor Advisory
- http://securitytracker.com/id?1014954
- http://www.debian.org/security/2005/dsa-838
- http://www.debian.org/security/2005/dsa-866
- http://www.debian.org/security/2005/dsa-868
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:169
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:170
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:174
- http://www.mozilla.org/security/announce/mfsa2005-58.html
- http://www.novell.com/linux/security/advisories/2005_58_mozilla.html
- http://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00004.html
- http://www.redhat.com/support/errata/RHSA-2005-785.html
- http://www.redhat.com/support/errata/RHSA-2005-789.html
- http://www.redhat.com/support/errata/RHSA-2005-791.html
- http://www.securityfocus.com/bid/14923
- http://www.securityfocus.com/bid/15495
- http://www.ubuntu.com/usn/usn-200-1
- http://www.vupen.com/english/advisories/2005/1824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22376
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10767
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.