Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade seamonkeyUpgrade firefox-jaUpgrade linux-mozilla-develUpgrade linux-seamonkey-develUpgrade linux-mozillaUpgrade mozillaUpgrade mozilla-thunderbirdUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-firefoxUpgrade linux-firefox-develUpgrade lightningUpgrade linux-seamonkey | Dec 10, 2025 | Feb 24, 2007 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Feb 7, 2007 |
| Mfsa2007 05 | — | Upgrade to Mozilla Firefox version 1.5.0.10Upgrade to Mozilla Firefox version 2.0.0.2 | Jun 14, 2012 | Feb 7, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.8 | Feb 3, 2012 | Feb 7, 2007 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libnspr4Upgrade libnss3Upgrade firefox | Nov 8, 2024 | Feb 7, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub