CVE-2007-3737Mozilla Firefox vulnerability

6 documents5 sources
Severity
9.3CRITICALNVD
EPSS
10.0%
top 6.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 3

Description

Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox5 versions+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-jf32-xh25-m8f3: Mozilla Firefox before 22022-05-03

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2007-07-20
Red Hat
security flaw2007-07-18

💬Community

2
Bugzilla
CVE-2007-3737 security flaw2018-08-16
Bugzilla
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)2007-07-17