CVE-2007-0994Code Injection in Mozilla Firefox

CWE-94Code Injection6 documents4 sources
Severity
6.8MEDIUMNVD
EPSS
3.2%
top 13.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateMay 3

Description

A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox1.51.5.0.10+1
NVDmozilla/seamonkey1.01.0.8+1

Also affects: Debian Linux 3.1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-qp4j-3v3v-gvgq: A regression error in Mozilla Firefox 22022-05-03

📋Vendor Advisories

1
Red Hat
security flaw2007-03-05

💬Community

3
Bugzilla
CVE-2007-0994 security flaw2018-08-16
Bugzilla
CVE-2007-0994 Thunderbird arbitrary javascript command execution2007-03-02
Bugzilla
CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0994, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0002007-02-26