Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey. | Oct 30, 2017 | Oct 21, 2007 |
| Mfsa2007 33 | — | Upgrade to Mozilla Firefox version 2.0.0.8 | Jun 14, 2012 | Oct 21, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.5 | Feb 3, 2012 | Oct 21, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Oct 21, 2007 |
| Suse | — | Upgrade seamonkey-mailUpgrade MozillaFirefoxUpgrade mozilla-develUpgrade mozilla-deatUpgrade seamonkey-spellcheckerUpgrade mozilla-ircUpgrade mozilla-venkmanUpgrade seamonkey-ircUpgrade seamonkeyUpgrade mozilla-csUpgrade mozilla-mailUpgrade mozilla-calendarUpgrade suse-releaseUpgrade mozilla-dom-inspectorUpgrade mozillaUpgrade seamonkey-venkmanUpgrade MozillaFirefox-translationsUpgrade seamonkey-dom-inspectorUpgrade mozilla-hu | Feb 17, 2015 | Oct 21, 2007 |
| Ubuntu | — | Upgrade firefoxUpgrade mozilla-thunderbird | Nov 8, 2024 | Oct 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub