Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Firefox exploit targets zero day vulns
John Leyden, The Register 2005-05-09

Security researchers have discovered two unpatched vulnerabilities in Firefox, the popular alternative web browser. The security bugs affect even the latest version of Firefox (version 1.0.3) and create a means for attackers to seize control of vulnerable systems using cross-site scripting attacks.

Comments Mode:
Firefox exploit targets zero day vulns 2005-05-09
TJ (4 replies)
Firefox exploit targets zero day vulns 2005-05-10
David Prinzing
Firefox exploit targets zero day vulns 2005-05-10
Anonymous (2 replies)
Read the vulnerability description. "Executes code under user perms". Pretty common for most application vulns. Quite a bit different than 'executes perms as activex admin user' or 'executes arbitrary code under IE that is tied into the rest of the operating system'. Vulnerbilities are vulnerabilites...but poor design is poor design. I believe the 'true' context of the 'more secure' argument is based on design principles. Besides...take a look at how many vulns. are available for IE (closed source) compared to FireFox (open source). Take a standard security course, and they teach you that 10 hidden vulns. exist for each 1 discovered (using closed proprietary code).

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11119/31816#31816
Firefox exploit targets zero day vulns 2005-05-10
David Prinzing
Firefox exploit targets zero day vulns 2005-05-10
Anonymous (2 replies)
Firefox exploit targets zero day vulns 2005-05-10
Anonymous (1 replies)
Firefox exploit targets zero day vulns 2005-05-11
Coldman (2 replies)
Firefox exploit targets zero day vulns 2005-05-12
Anonymous (1 replies)







 

Privacy Statement
Copyright 2009, SecurityFocus