CVE-2007-1092
published 2007-02-26CVE-2007-1092: Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.07%
93.5th percentile
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 1.0.7 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jg4-hw5g-ph9p: Mozilla Firefox 1
ghsa_unreviewed·2022-05-03
CVE-2007-1092 [HIGH] GHSA-9jg4-hw5g-ph9p: Mozilla Firefox 1
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
GHSA
GHSA-8vcf-c8hj-wp5r: Mozilla Firefox 2
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2007-1256 [CRITICAL] CWE-119 GHSA-8vcf-c8hj-wp5r: Mozilla Firefox 2
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.
Ubuntu
Firefox regression
vendor_ubuntu·2007-03-02·CVSS 5.0
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: Firefox regression
USN-428-1 fixed vulnerabilities in Firefox 1.5. However, changes to
library paths caused applications depending on libnss3 to fail to start
up. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Several flaws have been found that could be used to perform Cross-site
scripting attacks. A malicious web site could exploit these to modify
the contents or steal confidential data (such as passwords) from other
opened web pages. (CVE-2006-6077, CVE-2007-0780, CVE-2007-0800,
CVE-2007-0981, CVE-2007-0995, CVE-2007-0996)
The SSLv2 protocol support in the NSS library did not sufficiently
check the validity of public keys presented with a SSL certificate. A
malicious SSL web site using SSLv2 could pot
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-03-01·CVSS 5.0
CVE-2007-1092 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Several flaws have been found that could be used to perform Cross-site
scripting attacks. A malicious web site could exploit these to modify
the contents or steal confidential data (such as passwords) from other
opened web pages. (CVE-2006-6077, CVE-2007-0780, CVE-2007-0800,
CVE-2007-0981, CVE-2007-0995, CVE-2007-0996)
The SSLv2 protocol support in the NSS library did not sufficiently
check the validity of public keys presented with a SSL certificate. A
malicious SSL web site using SSLv2 could potentially exploit this to
execute arbitrary code with the user's privileges. (CVE-2007-0008)
The SSLv2 protocol support in the NSS library did not sufficiently
verify the validity of client master keys presented in an SSL client
ce
Red Hat
security flaw
vendor_redhat·2007-02-23·CVSS 9.3
CVE-2007-1092 [CRITICAL] security flaw
security flaw
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-1092 security flaw
bugzilla·2018-08-16·CVSS 9.3
CVE-2007-1092 [CRITICAL] CVE-2007-1092 security flaw
CVE-2007-1092 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
bugzilla·2007-03-01·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981, CVE-2007-1092)
+++ This bug was initially created as a clone of Bug #229802 +++
The Mozilla project is releasing Thunderbird 1.5.0.10 to fix several flaws:
mfsa2007-01
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla pa
ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.ascftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://archives.neohapsis.com/archives/fulldisclosure/2007-02/0525.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.htmlhttp://osvdb.org/32103http://secunia.com/advisories/24333http://secunia.com/advisories/24343http://secunia.com/advisories/24384http://secunia.com/advisories/24395http://secunia.com/advisories/24457http://secunia.com/advisories/24650http://securityreason.com/securityalert/2302http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131http://www.kb.cert.org/vuls/id/393921http://www.mandriva.com/security/advisories?name=MDKSA-2007:050http://www.mozilla.org/security/announce/2007/mfsa2007-08.htmlhttp://www.novell.com/linux/security/advisories/2007_22_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0078.htmlhttp://www.securityfocus.com/archive/1/461024/100/0/threadedhttp://www.securityfocus.com/bid/22679http://www.securitytracker.com/id?1017701http://www.ubuntu.com/usn/usn-428-1https://bugzilla.mozilla.org/show_bug.cgi?id=371321https://exchange.xforce.ibmcloud.com/vulnerabilities/32647https://exchange.xforce.ibmcloud.com/vulnerabilities/32648https://issues.rpath.com/browse/RPL-1103https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11158ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.ascftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://archives.neohapsis.com/archives/fulldisclosure/2007-02/0525.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.htmlhttp://osvdb.org/32103http://secunia.com/advisories/24333http://secunia.com/advisories/24343http://secunia.com/advisories/24384http://secunia.com/advisories/24395http://secunia.com/advisories/24457http://secunia.com/advisories/24650http://securityreason.com/securityalert/2302http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131http://www.kb.cert.org/vuls/id/393921http://www.mandriva.com/security/advisories?name=MDKSA-2007:050http://www.mozilla.org/security/announce/2007/mfsa2007-08.htmlhttp://www.novell.com/linux/security/advisories/2007_22_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0078.htmlhttp://www.securityfocus.com/archive/1/461024/100/0/threadedhttp://www.securityfocus.com/bid/22679http://www.securitytracker.com/id?1017701http://www.ubuntu.com/usn/usn-428-1https://bugzilla.mozilla.org/show_bug.cgi?id=371321https://exchange.xforce.ibmcloud.com/vulnerabilities/32647https://exchange.xforce.ibmcloud.com/vulnerabilities/32648https://issues.rpath.com/browse/RPL-1103https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11158
2007-02-26
Published