CVE-2005-0401
FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
- Affected products
- Firefox, Mozilla Firefox, Red Hat
- Mozilla Firefox
- = 0.8, 0.9, 0.9.1, 0.9.2, 0.9.3, 0.10, 0.10.1, 1.0
- Mozilla
- = 1.3, 1.4, 1.4.1, 1.5, 1.5.1, 1.6, 1.7, 1.7.1, 1.7.2, 1.7.3, 1.7.5
- Fix
- Available
- CVSS 2.0
- 5.1 MEDIUM
- EPSS
- 3.3% (87th percentile)
- NVD status
- Modified
- Published
- 2005-03-24
CVE-2005-0401 at NVD
No indexed exploits for CVE-2005-0401 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2005-0401 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.