GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade seamonkeyUpgrade linux-mozillaUpgrade lightningUpgrade mozilla-thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade linux-firefox-develUpgrade mozillaUpgrade linux-mozilla-develUpgrade firefox-jaUpgrade linux-seamonkey-develUpgrade linux-thunderbirdUpgrade linux-firefox | Dec 10, 2025 | Feb 24, 2007 |
| Gentoo Linux | — | Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey-bin. | Oct 30, 2017 | Feb 26, 2007 |
| Mfsa2007 04 | — | Upgrade to Mozilla Firefox version 2.0.0.2Upgrade to Mozilla Firefox version 1.5.0.10 | Jun 14, 2012 | Feb 26, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.8 | Feb 3, 2012 | Feb 26, 2007 |
| Suse | — | Upgrade mozilla-ircUpgrade mozilla-deatUpgrade seamonkeyUpgrade mozilla-csUpgrade seamonkey-venkmanUpgrade seamonkey-spellcheckerUpgrade mozilla-develUpgrade seamonkey-dom-inspectorUpgrade mozilla-dom-inspectorUpgrade mozilla-mailUpgrade MozillaFirefoxUpgrade mozilla-calendarUpgrade suse-releaseUpgrade seamonkey-mailUpgrade mozilla-venkmanUpgrade MozillaFirefox-translationsUpgrade mozillaUpgrade seamonkey-ircUpgrade mozilla-hu | Feb 17, 2015 | Feb 26, 2007 |
| Ubuntu | — | Upgrade firefoxUpgrade libnss3Upgrade libnspr4 | Nov 8, 2024 | Feb 26, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub