Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunnerUpgrade firefoxUpgrade xulrunner-develUpgrade xulrunner-devel-unstable | Dec 1, 2016 | Feb 22, 2010 |
| Freebsd | — | Upgrade linux-firefoxUpgrade seamonkeyUpgrade linux-firefox-develUpgrade thunderbirdUpgrade firefox | Dec 10, 2025 | Feb 18, 2010 |
| Gentoo Linux | — | Upgrade www-client/seamonkey-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird.Upgrade www-client/firefox.Upgrade www-client/seamonkey. | Oct 30, 2017 | Feb 22, 2010 |
| Mfsa2010 05 | — | Upgrade to Mozilla Firefox version 3.5.8Upgrade to Mozilla Firefox version 3.6Upgrade to Mozilla Firefox version 3.0.18 | Jun 14, 2012 | Feb 22, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.3 | Feb 3, 2012 | Feb 22, 2010 |
| Oracle_linux | — | Upgrade xulrunner-develUpgrade xulrunnerUpgrade xulrunner-devel-unstableUpgrade firefox | Oct 16, 2024 | Feb 21, 2010 |
| Suse | — | Upgrade mozilla-nss-32bitUpgrade mozilla-nss-x86Upgrade mozilla-nss-toolsUpgrade MozillaFirefoxUpgrade mozilla-xulrunner191Upgrade MozillaFirefox-translationsUpgrade orbit2Upgrade gconf2-x86Upgrade gconf2Upgrade mozilla-xulrunner190-translationsUpgrade libidlUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner190Upgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner190-x86Upgrade mozilla-nspr-x86Upgrade mozilla-xulrunner191-gnomevfsUpgrade libfreebl3-32bitUpgrade mozilla-xulrunner190-32bitUpgrade libfreebl3Upgrade mozilla-nsprUpgrade orbit2-x86Upgrade mozilla-nspr-32bitUpgrade mozilla-xulrunner191-x86Upgrade libfreebl3-x86Upgrade mozilla-nssUpgrade MozillaFirefox-branding-SLEDUpgrade MozillaFirefox-develUpgrade mozilla-xulrunner190-gnomevfsUpgrade gconf2-32bitUpgrade libidl-x86Upgrade mozilla-xulrunner191-translationsUpgrade orbit2-32bitUpgrade libidl-32bitUpgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-x86 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade xulrunner-1.9.1Upgrade firefox-3.0Upgrade xulrunner-1.9Upgrade firefox-3.5Upgrade abrowser | Nov 8, 2024 | Feb 22, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub