Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Oct 21, 2007 |
| Mfsa2007 35 | — | Upgrade to Mozilla Firefox version 2.0.0.8 | Jun 14, 2012 | Oct 21, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.5 | Feb 3, 2012 | Oct 21, 2007 |
| Oracle_linux | — | Upgrade firefox-develUpgrade firefox | Oct 16, 2024 | Oct 21, 2007 |
| Suse | — | Upgrade mozilla-dom-inspectorUpgrade seamonkey-mailUpgrade mozilla-ircUpgrade mozilla-mailUpgrade suse-releaseUpgrade mozilla-deatUpgrade seamonkey-dom-inspectorUpgrade seamonkey-spellcheckerUpgrade seamonkeyUpgrade mozillaUpgrade mozilla-develUpgrade mozilla-csUpgrade MozillaFirefoxUpgrade seamonkey-venkmanUpgrade mozilla-calendarUpgrade mozilla-huUpgrade mozilla-venkmanUpgrade seamonkey-ircUpgrade MozillaFirefox-translations | Feb 17, 2015 | Oct 21, 2007 |
| Ubuntu | — | Upgrade mozilla-thunderbirdUpgrade firefox | Nov 8, 2024 | Oct 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub