CVE-2007-3089
published 2007-06-06CVE-2007-3089: Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.77%
84.9th percentile
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.4 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w739-3fq5-fgvp: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-03·CVSS 4.3
CVE-2007-3089 [MEDIUM] GHSA-w739-3fq5-fgvp: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.
GHSA
GHSA-6p6h-7mm4-6mhv: Mozilla Firefox 2
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-3844 [MEDIUM] GHSA-6p6h-7mm4-6mhv: Mozilla Firefox 2
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
Red Hat
about: blank windows
vendor_redhat·2007-07-31·CVSS 4.3
CVE-2007-3844 [MEDIUM] about: blank windows
about: blank windows
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=250648
The Red Hat Product Security has rated this issue as having moderate security impact, a future update may address this flaw.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-07-20·CVSS 4.3
CVE-2007-3089 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-3734,
CVE-2007-3735)
Flaws were discovered in the JavaScript methods addEventListener and
setTimeout which could be used to inject script into another site in
violation of the browser's same-origin policy. A malicious web site
could exploit this to modify the contents, or steal confidential data
(such as passwords), of other web pages. (CVE-2007-3736)
Ronen Zilberman and Michal Zalewski discovered timing attacks in the
JavaScript engine's use of about:blank frames. A malicious web site
could exploit this to modify the content
Red Hat
security flaw
vendor_redhat·2007-06-04·CVSS 4.3
CVE-2007-3089 [MEDIUM] security flaw
security flaw
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3089 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2007-3089 [MEDIUM] CVE-2007-3089 security flaw
CVE-2007-3089 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.
Bugzilla
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
bugzilla·2007-07-17·CVSS 4.3
CVE-2007-3089 [MEDIUM] CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
Various flaws have been fixed in Firefox 2.0.0.5 Please see the upstream
advisories:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
We are affected by:
MFSA 2007-18
MFSA 2007-19
MFSA 2007-20
MFSA 2007-21
MFSA 2007-24
MFSA 2007-25
Discussion:
It should be noted that CVE-2007-3656 does not affect Thunderbird.
---
epiphany-2.18.3-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
firefox-2.0.0.5-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
devhelp-0.13-9.fc7 has been
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txtftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.aschttp://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lcamtuf.coredump.cx/ifsnatch/http://osvdb.org/38024http://secunia.com/advisories/25589http://secunia.com/advisories/26072http://secunia.com/advisories/26095http://secunia.com/advisories/26103http://secunia.com/advisories/26106http://secunia.com/advisories/26107http://secunia.com/advisories/26149http://secunia.com/advisories/26151http://secunia.com/advisories/26159http://secunia.com/advisories/26179http://secunia.com/advisories/26204http://secunia.com/advisories/26205http://secunia.com/advisories/26211http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/26460http://secunia.com/advisories/28135http://securityreason.com/securityalert/2781http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.debian.org/security/2007/dsa-1337http://www.debian.org/security/2007/dsa-1338http://www.debian.org/security/2007/dsa-1339http://www.gentoo.org/security/en/glsa/glsa-200708-09.xmlhttp://www.kb.cert.org/vuls/id/143297http://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-20.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0722.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0724.htmlhttp://www.securityfocus.com/archive/1/470446/100/0/threadedhttp://www.securityfocus.com/archive/1/474226/100/0/threadedhttp://www.securityfocus.com/archive/1/474542/100/0/threadedhttp://www.securityfocus.com/bid/24286http://www.securitytracker.com/id?1018412http://www.ubuntu.com/usn/usn-490-1http://www.us-cert.gov/cas/techalerts/TA07-199A.htmlhttp://www.vupen.com/english/advisories/2007/2564http://www.vupen.com/english/advisories/2007/4256https://bugzilla.mozilla.org/show_bug.cgi?id=381300https://bugzilla.mozilla.org/show_bug.cgi?id=381300https://bugzilla.mozilla.org/show_bug.cgi?id=382686https://bugzilla.mozilla.org/show_bug.cgi?id=382686https://exchange.xforce.ibmcloud.com/vulnerabilities/34701https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11122ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txtftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.aschttp://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.htmlhttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lcamtuf.coredump.cx/ifsnatch/http://osvdb.org/38024http://secunia.com/advisories/25589http://secunia.com/advisories/26072http://secunia.com/advisories/26095http://secunia.com/advisories/26103http://secunia.com/advisories/26106http://secunia.com/advisories/26107http://secunia.com/advisories/26149http://secunia.com/advisories/26151http://secunia.com/advisories/26159http://secunia.com/advisories/26179http://secunia.com/advisories/26204http://secunia.com/advisories/26205http://secunia.com/advisories/26211http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/26460http://secunia.com/advisories/28135http://securityreason.com/securityalert/2781http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.debian.org/security/2007/dsa-1337http://www.debian.org/security/2007/dsa-1338http://www.debian.org/security/2007/dsa-1339http://www.gentoo.org/security/en/glsa/glsa-200708-09.xmlhttp://www.kb.cert.org/vuls/id/143297http://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-20.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0722.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0724.htmlhttp://www.securityfocus.com/archive/1/470446/100/0/threadedhttp://www.securityfocus.com/archive/1/474226/100/0/threadedhttp://www.securityfocus.com/archive/1/474542/100/0/threadedhttp://www.securityfocus.com/bid/24286http://www.securitytracker.com/id?1018412http://www.ubuntu.com/usn/usn-490-1http://www.us-cert.gov/cas/techalerts/TA07-199A.html
+ 8 more references
2007-06-06
Published