Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | May 31, 2007 |
| Mfsa2007 16 | — | Upgrade to Mozilla Firefox version 1.5.0.12Upgrade to Mozilla Firefox version 2.0.0.4 | Jun 14, 2012 | May 31, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.2Upgrade to Mozilla SeaMonkey version 1.0.9 | Feb 3, 2012 | May 31, 2007 |
| Oracle_linux | — | Upgrade devhelpUpgrade yelpUpgrade firefoxUpgrade devhelp-develUpgrade firefox-devel | Oct 16, 2024 | Jun 1, 2007 |
| Suse | — | Upgrade mozilla-venkmanUpgrade seamonkey-venkmanUpgrade seamonkey-ircUpgrade seamonkey-mailUpgrade mozilla-calendarUpgrade MozillaFirefox-translationsUpgrade mozilla-develUpgrade mozilla-ircUpgrade MozillaThunderbird-translationsUpgrade MozillaFirefoxUpgrade mozilla-huUpgrade mozilla-mailUpgrade mozilla-csUpgrade mozilla-dom-inspectorUpgrade seamonkey-spellcheckerUpgrade seamonkeyUpgrade mozillaUpgrade MozillaThunderbirdUpgrade suse-releaseUpgrade mozilla-deatUpgrade seamonkey-dom-inspector | Feb 17, 2015 | May 31, 2007 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jun 1, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub