---
title: "CVE-2005-1477\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2005-1477?format=md
keywords: index, follow
---

# CVE-2005-1477

Publication date 9 May 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The install function in Firefox 1.0.3 allows remote web sites on the
browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to
execute arbitrary Javascript with chrome privileges, leading to arbitrary
code execution on the system when combined with vulnerabilities such as
CVE-2005-1476, as demonstrated using a javascript: URL as the package icon
and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Fixed 2.0.0.6+1-0ubuntu1 |
| 6.10 edgy | Fixed 2.0.0.6+0dfsg-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| firefox-granparadiso | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| lightning-sunbird | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| midbrowser | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1477)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2005-1477)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2005-1477)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2005-1477)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2005-1477>
