Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving originalTarget and DOM Range.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunnerUpgrade xulrunner-devel-unstableUpgrade firefoxUpgrade devhelpUpgrade yelpUpgrade devhelp-develUpgrade xulrunner-devel | Dec 1, 2016 | Jul 7, 2008 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Jul 7, 2008 |
| Mfsa2008 27 | — | Upgrade to Mozilla Firefox version 2.0.0.15 | Jun 14, 2012 | Jul 7, 2008 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.10 | Feb 3, 2012 | Jul 7, 2008 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade xulrunner-devel-unstableUpgrade devhelpUpgrade xulrunnerUpgrade yelpUpgrade firefoxUpgrade devhelp-devel | Oct 16, 2024 | Jul 7, 2008 |
| Suse | — | Upgrade MozillaFirefox-translationsUpgrade seamonkeyUpgrade MozillaFirefoxUpgrade seamonkey-dom-inspectorUpgrade suse-releaseUpgrade seamonkey-venkmanUpgrade seamonkey-mailUpgrade seamonkey-spellcheckerUpgrade seamonkey-irc | Feb 17, 2015 | Jul 7, 2008 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jul 7, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub