security flaw
Published Jul 13, 2005
7.5
HIGHCVSS 2.0
EPSS 3.26%
Description
The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.
Affected products
No data.
- 0.8
- 0.9
- 0.9
- 0.9.1
- 0.9.2
- 0.9.3
- 0.10
- 0.10.1
- 1.0
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.4
- 1.3
- 1.4
- 1.4
- 1.4.1
- 1.5
- 1.5
- 1.5
- 1.5
- 1.5.1
- 1.6
- 1.6
- 1.6
- 1.7
- 1.7
- 1.7
- 1.7
- 1.7
- 1.7
- 1.7.1
- 1.7.2
- 1.7.3
- 1.7.5
- 1.7.6
- 1.7.7
- 1.7.8
No data.
Red Hat Enterprise Linux 4
devhelp-0:0.9.2-2.4.6
Fixed · RHSA-2005:587
Red Hat Enterprise Linux 4
firefox-0:1.0.6-1.4.1
Fixed · RHSA-2005:586
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | devhelp-0:0.9.2-2.4.6 | Fixed | RHSA-2005:587 |
| Red Hat Enterprise Linux 4 | firefox-0:1.0.6-1.4.1 | Fixed | RHSA-2005:586 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.26% (0.03264) | 87.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.26% (0.03264) | 86.73th | v5 (v2026.06.15) |
| Mar 30, 2025 | 3.73% (0.03727) | 86.89th | v4 (v2025.03.14) |
| Mar 29, 2025 | 10.54% (0.10538) | 88.69th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.73% (0.03727) | 87.20th | v4 (v2025.03.14) |
| Jan 18, 2025 | 0.79% (0.00790) | 81.49th | v3 (v2023.03.01) |
| Jun 19, 2024 | 2.31% (0.02305) | 89.76th | v3 (v2023.03.01) |
| Nov 2, 2023 | 4.95% (0.04947) | 91.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 6.84% (0.06839) | 92.76th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
No CWE recorded.
References (23)
- http://bugzilla.mozilla.org/show_bug.cgi?id=289940 x_refsource_MISC
- http://secunia.com/advisories/16043 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/16044 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/16059 third-party-advisoryx_refsource_SECUNIA
- http://www.ciac.org/ciac/bulletins/p-252.shtml third-party-advisorygovernment-resourcex_refsource_CIAC
- http://www.debian.org/security/2005/dsa-810 vendor-advisoryx_refsource_DEBIAN
- http://www.mozilla.org/security/announce/mfsa2005-45.html x_refsource_CONFIRMPatchVendor Advisory
- http://www.networksecurity.fi/advisories/netscape-multiple-issues.html x_refsource_MISC
- http://www.novell.com/linux/security/advisories/2005_18_sr.html vendor-advisoryx_refsource_SUSE
- http://www.novell.com/linux/security/advisories/2005_45_mozilla.html vendor-advisoryx_refsource_SUSE
- http://www.redhat.com/support/errata/RHSA-2005-586.html vendor-advisoryx_refsource_REDHAT
- http://www.redhat.com/support/errata/RHSA-2005-587.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/14242 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2005/1075 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2005-2260 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=160202 vendor-advisoryx_refsource_FEDORA
- https://bugzilla.redhat.com/show_bug.cgi?id=1617693 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2005-2260
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100013 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10132 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1226 vdb-entrysignaturex_refsource_OVAL
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A742 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2005-2260
Change history (0)
No recorded changes yet.