CVE-2007-5338Mozilla Firefox vulnerability

CWE-16CWE-2647 documents5 sources
Severity
9.3CRITICALNVD
EPSS
5.0%
top 10.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 1

Description

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDmozilla/firefox2.0.0.7

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5q38-h7gf-fmjx: Mozilla Firefox before 22022-05-01

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2007-10-23
Ubuntu
Firefox vulnerabilities2007-10-22
Red Hat
security flaw2007-10-18

💬Community

2
Bugzilla
CVE-2007-5338 security flaw2018-08-16
Bugzilla
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)2007-10-16
CVE-2007-5338 — Mozilla Firefox vulnerability | cvebase