PT-2007-2424 · Mozilla+2 · Firefox+3

Publicado

2007-02-23

·

Atualizado

2019-10-09

·

CVE-2007-0994

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions 1.x through 1.5.0.9 Mozilla Firefox versions 2.x through 2.0.0.1 SeaMonkey versions 1.0 through 1.0.7 SeaMonkey versions 1.1 through 1.1.0
Description: A regression error allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an img, link, or style tag. This bypasses access checks and executes code with chrome privileges.
Recommendations: For Mozilla Firefox versions 1.x through 1.5.0.9, update to version 1.5.0.10 or later. For Mozilla Firefox versions 2.x through 2.0.0.1, update to version 2.0.0.2 or later. For SeaMonkey versions 1.0 through 1.0.7, update to version 1.0.8 or later. For SeaMonkey versions 1.1 through 1.1.0, update to version 1.1.1 or later.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-0994
DSA-1336-1
HPSBUX02153
RHSA-2007:0077
RHSA-2007:0079
RHSA-2007:0097
RHSA-2007_0077
RHSA-2007_0079
RHSA-2007_0097

Produtos afetados

Hp-Ux
Firefox
Red Hat
Seamonkey