Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefoxUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade mozilla-thunderbirdUpgrade linux-firefoxUpgrade linux-firefox-develUpgrade linux-mozilla-develUpgrade linux-thunderbirdUpgrade firefox-jaUpgrade linux-seamonkey-develUpgrade mozillaUpgrade linux-mozilla | Dec 10, 2025 | Jul 19, 2007 |
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner. | Oct 30, 2017 | Jun 6, 2007 |
| Mfsa2007 20 | — | Upgrade to Mozilla Firefox version 2.0.0.5 | Jun 14, 2012 | Jun 6, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.3 | Feb 3, 2012 | Jun 6, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Jun 6, 2007 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-other | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jun 6, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub