Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunner-devel-unstableUpgrade devhelpUpgrade devhelp-develUpgrade xulrunnerUpgrade firefoxUpgrade xulrunner-develUpgrade yelp | Dec 1, 2016 | Jul 7, 2008 |
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade net-libs/xulrunner. | Oct 30, 2017 | Jul 7, 2008 |
| Mfsa2008 23 | — | Upgrade to Mozilla Firefox version 2.0.0.15Upgrade to Mozilla Firefox version 3.0 | Jun 14, 2012 | Jul 7, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.10 | Feb 3, 2012 | Jul 7, 2008 |
| Oracle_linux | — | Upgrade devhelp-develUpgrade devhelpUpgrade yelpUpgrade firefoxUpgrade xulrunner-develUpgrade xulrunner-devel-unstableUpgrade xulrunner | Oct 16, 2024 | Jul 7, 2008 |
| Suse | — | Upgrade MozillaFirefoxUpgrade seamonkeyUpgrade MozillaFirefox-translationsUpgrade seamonkey-spellcheckerUpgrade seamonkey-venkmanUpgrade suse-releaseUpgrade seamonkey-mailUpgrade seamonkey-dom-inspectorUpgrade seamonkey-irc | Feb 17, 2015 | Jul 7, 2008 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 7, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub