Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Jul 18, 2007 |
| Mfsa2007 19 | — | Upgrade to Mozilla Firefox version 2.0.0.5 | Jun 14, 2012 | Jul 18, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.3 | Feb 3, 2012 | Jul 18, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Jul 18, 2007 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 18, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub