CVE-2007-5334Mozilla Firefox vulnerability

CWE-167 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
11.6%
top 6.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 1

Description

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attribute.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDmozilla/firefox2.0.0.7

Patches

🔴Vulnerability Details

1
GHSA
GHSA-367f-4w4m-gh7p: Mozilla Firefox before 22022-05-01

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2007-10-23
Ubuntu
Firefox vulnerabilities2007-10-22
Red Hat
security flaw2007-10-18

💬Community

2
Bugzilla
CVE-2007-5334 security flaw2018-08-16
Bugzilla
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)2007-10-16
CVE-2007-5334 — Mozilla Firefox vulnerability | cvebase