The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Nov 13, 2007 |
| Mfsa2007 37 | — | Upgrade to Mozilla Firefox version 2.0.0.10 | Jun 14, 2012 | Nov 13, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.7 | Feb 3, 2012 | Nov 13, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Nov 14, 2007 |
| Suse | — | Upgrade epiphanyUpgrade mozilla-dom-inspectorUpgrade epiphany-develUpgrade mozilla-xulrunner181-l10nUpgrade suse-releaseUpgrade mozilla-calendarUpgrade mozilla-deatUpgrade mozilla-xulrunner181-32bitUpgrade epiphany-docUpgrade mozilla-xulrunner181-64bitUpgrade MozillaFirefox-translationsUpgrade seamonkey-venkmanUpgrade mozilla-xulrunner181-develUpgrade epiphany-langUpgrade mozillaUpgrade seamonkey-dom-inspectorUpgrade MozillaFirefoxUpgrade mozilla-huUpgrade seamonkey-spellcheckerUpgrade seamonkeyUpgrade seamonkey-mailUpgrade mozilla-venkmanUpgrade epiphany-extensions-langUpgrade mozilla-develUpgrade mozilla-ircUpgrade seamonkey-ircUpgrade epiphany-extensionsUpgrade mozilla-xulrunner181Upgrade mozilla-csUpgrade mozilla-mail | Feb 17, 2015 | Nov 13, 2007 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Nov 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub