Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-thunderbirdUpgrade mozilla-thunderbirdUpgrade mozillaUpgrade linux-firefox-develUpgrade linux-firefoxUpgrade lightningUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade linux-mozillaUpgrade seamonkeyUpgrade firefox-jaUpgrade linux-mozilla-develUpgrade linux-seamonkey-develUpgrade firefox | Dec 10, 2025 | Feb 24, 2007 |
| Mfsa2007 08 | — | Upgrade to Mozilla Firefox version 2.0.0.2Upgrade to Mozilla Firefox version 1.5.0.10 | Jun 14, 2012 | Feb 26, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.8 | Feb 3, 2012 | Feb 26, 2007 |
| Ubuntu | — | Upgrade libnss3Upgrade libnspr4Upgrade firefox | Nov 8, 2024 | Feb 26, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub