Vulnerability record · CVE-2005-2265 · published 13 July 2005
CVE-2005-2265: Firefox and Mozilla InstallVersion.compareTo type confusion crash
Mozilla · Firefox
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 mishandle a call to InstallVersion.compareTo when an object is passed instead of a string, causing an access violation and browser crash. The same flaw is described as possibly allowing arbitrary code execution, though the record does not confirm that outcome.
Description
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityCVSS rates it medium with availability-only impact, but the high EPSS score and public exploit tag raise concern for unpatched legacy browsers.
What it is
Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 mishandle a call to InstallVersion.compareTo when an object is passed instead of a string, causing an access violation and browser crash. The same flaw is described as possibly allowing arbitrary code execution, though the record does not confirm that outcome.
Impact
A remote attacker can crash the affected browser, causing denial of service. The record notes possible arbitrary code execution, but no confirmed code-execution impact is documented.
Attack surface
Reachable remotely over the network with no authentication and no user interaction per the CVSS vector AV:N/AC:L/Au:N, likely by delivering crafted content that triggers the InstallVersion.compareTo call. The description does not specify the exact delivery mechanism.
Exploitation
Not listed in CISA KEV and no ransomware use is documented; EPSS is 0.68097 (99.291st percentile), and a Mozilla Bugzilla reference carries an Exploit tag, indicating public exploit interest.
What to do
- Upgrade Firefox to 1.0.5 or later and Mozilla to 1.7.9 or later, or apply the vendor patch referenced in Mozilla security advisory mfsa2005-50.
- Apply the relevant Linux distribution errata (Debian DSA-810, Red Hat RHSA-2005-586/587/601, Novell/SUSE advisories) if using packaged browsers.
- Retire or isolate Netscape 8.0.2 and 7.2, which are listed as affected and are no longer maintained.
- Where legacy browsers cannot be patched, restrict browsing to trusted sites and block untrusted script or plugin content.
Detection
- Monitor browser crash reports and access violation events tied to Firefox, Mozilla, or Netscape processes.
- Hunt for unexpected child processes or code execution originating from browser processes on hosts running the affected versions.
- Use OVAL definitions referenced in the record to scan for vulnerable Firefox, Mozilla, and Netscape installations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2265 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2265), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.