Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird. | Oct 30, 2017 | Aug 7, 2007 |
| Mfsa2007 26 | — | Upgrade to Mozilla Firefox version 2.0.0.6 | Jun 14, 2012 | Aug 7, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.4 | Feb 3, 2012 | Aug 7, 2007 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.13Upgrade to Mozilla Thunderbird version 2.0.0.6 | Feb 22, 2012 | Aug 7, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Aug 8, 2007 |
| Suse | — | Upgrade mozilla-ircUpgrade seamonkey-venkmanUpgrade mozilla-csUpgrade seamonkey-spellcheckerUpgrade mozilla-dom-inspectorUpgrade mozilla-deatUpgrade seamonkey-dom-inspectorUpgrade seamonkeyUpgrade suse-releaseUpgrade mozillaUpgrade MozillaFirefoxUpgrade seamonkey-ircUpgrade mozilla-develUpgrade MozillaFirefox-translationsUpgrade seamonkey-mailUpgrade mozilla-huUpgrade mozilla-calendarUpgrade mozilla-mailUpgrade mozilla-venkman | Feb 17, 2015 | Aug 7, 2007 |
| Ubuntu | — | Upgrade mozilla-thunderbirdUpgrade firefox | Nov 8, 2024 | Aug 8, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub