CVE-2007-3736
published 2007-07-18CVE-2007-3736: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context"…
PriorityP414medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.35%
68.7th percentile
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | seamonkey | <= 2.0.2 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox/thunderbird/seamonkey: XSS using addEventListener and setTimeout on a wrapped object (MFSA 2010-12)
vendor_redhat·2010-03-23·CVSS 4.3
CVE-2010-0171 [MEDIUM] CWE-79 firefox/thunderbird/seamonkey: XSS using addEventListener and setTimeout on a wrapped object (MFSA 2010-12)
firefox/thunderbird/seamonkey: XSS using addEventListener and setTimeout on a wrapped object (MFSA 2010-12)
Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-07-20·CVSS 4.3
CVE-2007-3089 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-3734,
CVE-2007-3735)
Flaws were discovered in the JavaScript methods addEventListener and
setTimeout which could be used to inject script into another site in
violation of the browser's same-origin policy. A malicious web site
could exploit this to modify the contents, or steal confidential data
(such as passwords), of other web pages. (CVE-2007-3736)
Ronen Zilberman and Michal Zalewski discovered timing attacks in the
JavaScript engine's use of about:blank frames. A malicious web site
could exploit this to modify the content
Red Hat
security flaw
vendor_redhat·2007-07-18·CVSS 4.3
CVE-2007-3736 [MEDIUM] security flaw
security flaw
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
GHSA
GHSA-wchf-965x-6qj3: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-03
CVE-2007-3736 [MEDIUM] GHSA-wchf-965x-6qj3: Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
GHSA
GHSA-vv9f-p8wq-vp27: Mozilla Firefox 3
ghsa_unreviewed·2022-05-02·CVSS 4.3
CVE-2010-0171 [MEDIUM] CWE-79 GHSA-vv9f-p8wq-vp27: Mozilla Firefox 3
Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3736 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2007-3736 [MEDIUM] CVE-2007-3736 security flaw
CVE-2007-3736 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.
Bugzilla
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
bugzilla·2007-07-17·CVSS 4.3
CVE-2007-3089 [MEDIUM] CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
Various flaws have been fixed in Firefox 2.0.0.5 Please see the upstream
advisories:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
We are affected by:
MFSA 2007-18
MFSA 2007-19
MFSA 2007-20
MFSA 2007-21
MFSA 2007-24
MFSA 2007-25
Discussion:
It should be noted that CVE-2007-3656 does not affect Thunderbird.
---
epiphany-2.18.3-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
firefox-2.0.0.5-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
devhelp-0.13-9.fc7 has been
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txtftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/25589http://secunia.com/advisories/26072http://secunia.com/advisories/26095http://secunia.com/advisories/26103http://secunia.com/advisories/26106http://secunia.com/advisories/26107http://secunia.com/advisories/26149http://secunia.com/advisories/26151http://secunia.com/advisories/26159http://secunia.com/advisories/26179http://secunia.com/advisories/26204http://secunia.com/advisories/26205http://secunia.com/advisories/26211http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/26460http://secunia.com/advisories/28135http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.debian.org/security/2007/dsa-1337http://www.debian.org/security/2007/dsa-1338http://www.debian.org/security/2007/dsa-1339http://www.gentoo.org/security/en/glsa/glsa-200708-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-19.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0722.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0724.htmlhttp://www.securityfocus.com/archive/1/474226/100/0/threadedhttp://www.securityfocus.com/archive/1/474542/100/0/threadedhttp://www.securityfocus.com/bid/24946http://www.securitytracker.com/id?1018410http://www.ubuntu.com/usn/usn-490-1http://www.vupen.com/english/advisories/2007/2564http://www.vupen.com/english/advisories/2007/4256https://exchange.xforce.ibmcloud.com/vulnerabilities/35462https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11749ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txtftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/25589http://secunia.com/advisories/26072http://secunia.com/advisories/26095http://secunia.com/advisories/26103http://secunia.com/advisories/26106http://secunia.com/advisories/26107http://secunia.com/advisories/26149http://secunia.com/advisories/26151http://secunia.com/advisories/26159http://secunia.com/advisories/26179http://secunia.com/advisories/26204http://secunia.com/advisories/26205http://secunia.com/advisories/26211http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/26460http://secunia.com/advisories/28135http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.debian.org/security/2007/dsa-1337http://www.debian.org/security/2007/dsa-1338http://www.debian.org/security/2007/dsa-1339http://www.gentoo.org/security/en/glsa/glsa-200708-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-19.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0722.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0724.htmlhttp://www.securityfocus.com/archive/1/474226/100/0/threadedhttp://www.securityfocus.com/archive/1/474542/100/0/threadedhttp://www.securityfocus.com/bid/24946http://www.securitytracker.com/id?1018410http://www.ubuntu.com/usn/usn-490-1http://www.vupen.com/english/advisories/2007/2564http://www.vupen.com/english/advisories/2007/4256https://exchange.xforce.ibmcloud.com/vulnerabilities/35462https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11749
2007-07-18
Published