CVE-2007-5335
published 2007-10-24CVE-2007-5335: Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to…
PriorityP411medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.29%
67.4th percentile
Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.7 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-10-22·CVSS 4.0
CVE-2007-5334 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines.
By tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5336,
CVE-2007-5339, CVE-2007-5340)
Michal Zalewski discovered that the onUnload event handlers were
incorrectly able to access information outside the old page content.
A malicious web site could exploit this to modify the contents, or steal
confidential data (such as passwords), of the next loaded web page.
(CVE-2007-1095)
Stefano Di Paola discovered that Firefox did not correctly request
Digest Authentications. A malicious web site could exploit this to
inject arbitrary HTTP headers or perform session splitting attacks
aga
GHSA
GHSA-7m2r-r8f2-p7vc: Mozilla Firefox 2
ghsa_unreviewed·2022-05-01
CVE-2007-5335 [MEDIUM] CWE-200 GHSA-7m2r-r8f2-p7vc: Mozilla Firefox 2
Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/42470http://secunia.com/advisories/27335http://secunia.com/advisories/27387http://secunia.com/advisories/27665http://www.gentoo.org/security/en/glsa/glsa-200711-14.xmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=390983https://exchange.xforce.ibmcloud.com/vulnerabilities/37428https://usn.ubuntu.com/535-1/https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.htmlhttp://osvdb.org/42470http://secunia.com/advisories/27335http://secunia.com/advisories/27387http://secunia.com/advisories/27665http://www.gentoo.org/security/en/glsa/glsa-200711-14.xmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=390983https://exchange.xforce.ibmcloud.com/vulnerabilities/37428https://usn.ubuntu.com/535-1/https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html
2007-10-24
Published