Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/seamonkey. | Oct 30, 2017 | Nov 26, 2007 |
| Mfsa2007 39 | — | Upgrade to Mozilla Firefox version 2.0.0.10 | Jun 14, 2012 | Nov 26, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.7 | Feb 3, 2012 | Nov 26, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade firefox-devel | Oct 16, 2024 | Nov 26, 2007 |
| Suse | — | Upgrade mozilla-xulrunner181-32bitUpgrade mozilla-xulrunner181-64bitUpgrade mozilla-huUpgrade mozilla-dom-inspectorUpgrade mozilla-deatUpgrade mozillaUpgrade suse-releaseUpgrade seamonkey-dom-inspectorUpgrade epiphany-docUpgrade epiphany-langUpgrade mozilla-venkmanUpgrade mozilla-develUpgrade MozillaFirefox-translationsUpgrade MozillaFirefoxUpgrade seamonkey-ircUpgrade mozilla-mailUpgrade epiphany-extensionsUpgrade mozilla-csUpgrade epiphany-extensions-langUpgrade seamonkeyUpgrade mozilla-ircUpgrade seamonkey-spellcheckerUpgrade seamonkey-mailUpgrade mozilla-xulrunner181-l10nUpgrade epiphanyUpgrade epiphany-develUpgrade seamonkey-venkmanUpgrade mozilla-xulrunner181-develUpgrade mozilla-xulrunner181Upgrade mozilla-calendar | Feb 17, 2015 | Nov 26, 2007 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Nov 26, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub