CVE-2007-1095Mozilla Firefox vulnerability

9 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
4.4%
top 10.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 1

Description

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDmozilla/firefox2.0.0.7+55
NVDmozilla/seamonkey1.1.4+14

🔴Vulnerability Details

1
GHSA
GHSA-3p9c-7xp5-vwmq: Mozilla Firefox before 22022-05-01

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2007-10-23
Ubuntu
Firefox vulnerabilities2007-10-22
Red Hat
security flaw2007-02-23

💬Community

3
Bugzilla
CVE-2007-1095 security flaw2018-08-16
Bugzilla
CVE-2007-6110 htdig htsearch XSS vulnerability2007-11-26
Bugzilla
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)2007-10-16
CVE-2007-1095 — Mozilla Firefox vulnerability | cvebase