PT-2007-2523 · Mozilla+1 · Firefox+2

Michal Zalewski

·

Published

2007-02-26

·

Updated

2018-10-16

·

CVE-2007-1095

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions prior to 2.0.0.8 SeaMonkey versions prior to 1.1.5
Description The issue arises from the improper implementation of JavaScript onUnload handlers, allowing remote attackers to execute specific JavaScript code. This enables access to the location DOM hierarchy within the context of the next website visited by a client.
Recommendations For Mozilla Firefox versions prior to 2.0.0.8, update to version 2.0.0.8 or later to resolve the issue. For SeaMonkey versions prior to 1.1.5, update to version 1.1.5 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1095
DSA-1392-1
DSA-1396-1
DSA-1401-1
DTSA-69-1
DTSA-80-1
HPSBUX02153
RHSA-2007:0979
RHSA-2007:0980
RHSA-2007:0981
RHSA-2007_0979
RHSA-2007_0980
RHSA-2007_0981

Affected Products

Firefox
Red Hat
Seamonkey