PT-2007-2424 · Mozilla+2 · Firefox+3

Published

2007-02-23

·

Updated

2019-10-09

·

CVE-2007-0994

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions 1.x through 1.5.0.9 Mozilla Firefox versions 2.x through 2.0.0.1 SeaMonkey versions 1.0 through 1.0.7 SeaMonkey versions 1.1 through 1.1.0
Description: A regression error allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an img, link, or style tag. This bypasses access checks and executes code with chrome privileges.
Recommendations: For Mozilla Firefox versions 1.x through 1.5.0.9, update to version 1.5.0.10 or later. For Mozilla Firefox versions 2.x through 2.0.0.1, update to version 2.0.0.2 or later. For SeaMonkey versions 1.0 through 1.0.7, update to version 1.0.8 or later. For SeaMonkey versions 1.1 through 1.1.0, update to version 1.1.1 or later.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0994
DSA-1336-1
HPSBUX02153
RHSA-2007:0077
RHSA-2007:0079
RHSA-2007:0097
RHSA-2007_0077
RHSA-2007_0079
RHSA-2007_0097

Affected Products

Hp-Ux
Firefox
Red Hat
Seamonkey