CVE-2007-5339
published 2007-10-21CVE-2007-5339: Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of…
PriorityP413medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.43%
87.6th percentile
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.7 | — |
| mozilla | seamonkey | <= 1.1.4 | — |
| mozilla | thunderbird | <= 2.0.0.6 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2007-10-23·CVSS 4.0
CVE-2006-2894 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5339,
CVE-2007-5340)
Flaws were discovered in the file upload form control. By tricking
a user into opening a malicious web page, an attacker could force
arbitrary files from the user's computer to be uploaded without their
consent. (CVE-2006-2894, CVE-2007-3511)
Michal Zalewski discovered that the onUnload event handlers were
incorrectly able to access information outside the old page content. A
malicious web site could exploit this to modify the contents, or
steal confidential data (such as passwords), of the next l
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-10-22·CVSS 4.0
CVE-2007-5334 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines.
By tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5336,
CVE-2007-5339, CVE-2007-5340)
Michal Zalewski discovered that the onUnload event handlers were
incorrectly able to access information outside the old page content.
A malicious web site could exploit this to modify the contents, or steal
confidential data (such as passwords), of the next loaded web page.
(CVE-2007-1095)
Stefano Di Paola discovered that Firefox did not correctly request
Digest Authentications. A malicious web site could exploit this to
inject arbitrary HTTP headers or perform session splitting attacks
aga
Red Hat
security flaw
vendor_redhat·2007-10-18·CVSS 4.3
CVE-2007-5339 [MEDIUM] security flaw
security flaw
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
GHSA
GHSA-2v9q-c3g9-f96r: Multiple vulnerabilities in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2007-5339 [MEDIUM] CWE-20 GHSA-2v9q-c3g9-f96r: Multiple vulnerabilities in Mozilla Firefox before 2
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5339 security flaw
bugzilla·2018-08-16·CVSS 4.3
CVE-2007-5339 [MEDIUM] CVE-2007-5339 security flaw
CVE-2007-5339 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
Bugzilla
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)
bugzilla·2007-10-16·CVSS 6.8
CVE-2007-1095 [MEDIUM] Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)
Mozilla products security update (CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340)
Here is a rough breakdown of the flaws grouped by type. The official
definition of these issues can be found on the upstream security page here:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
Leveraging browser flaws, fooling users into possibly surrendering sensitive
information (Moderate):
CVE-2007-1095, CVE-2007-3511, CVE-2007-3844, CVE-2007-5334
Malformed web content could result in the execution of arbitrary commands
(Critical):
CVE-2007-5336, CVE-2007-5338, CVE-2007-5339, CVE-2007-5340
Digest Authentication requests can be used to conduct a response splitting
attack (Moderate):
CVE-2007-2292
http://bugs.gentoo.org/show_bug.cgi?id=196481http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579http://secunia.com/advisories/27276http://secunia.com/advisories/27298http://secunia.com/advisories/27311http://secunia.com/advisories/27313http://secunia.com/advisories/27315http://secunia.com/advisories/27325http://secunia.com/advisories/27326http://secunia.com/advisories/27327http://secunia.com/advisories/27335http://secunia.com/advisories/27336http://secunia.com/advisories/27356http://secunia.com/advisories/27360http://secunia.com/advisories/27383http://secunia.com/advisories/27387http://secunia.com/advisories/27403http://secunia.com/advisories/27414http://secunia.com/advisories/27425http://secunia.com/advisories/27480http://secunia.com/advisories/27665http://secunia.com/advisories/27680http://secunia.com/advisories/27704http://secunia.com/advisories/27744http://secunia.com/advisories/28179http://secunia.com/advisories/28363http://secunia.com/advisories/28398http://secunia.com/advisories/28636http://security.gentoo.org/glsa/glsa-200711-24.xmlhttp://securitytracker.com/id?1018834http://securitytracker.com/id?1018835http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.471007http://sunsolve.sun.com/search/document.do?assetkey=1-26-231441-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018977.1-1http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.htmlhttp://www.debian.org/security/2007/dsa-1391http://www.debian.org/security/2007/dsa-1392http://www.debian.org/security/2007/dsa-1396http://www.debian.org/security/2007/dsa-1401http://www.gentoo.org/security/en/glsa/glsa-200711-14.xmlhttp://www.kb.cert.org/vuls/id/559977http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202http://www.mandriva.com/security/advisories?name=MDVSA-2007:047http://www.mandriva.com/security/advisories?name=MDVSA-2008:047http://www.mozilla.org/security/announce/2007/mfsa2007-29.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0979.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0980.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0981.htmlhttp://www.securityfocus.com/archive/1/482876/100/200/threadedhttp://www.securityfocus.com/archive/1/482925/100/0/threadedhttp://www.securityfocus.com/archive/1/482932/100/200/threadedhttp://www.securityfocus.com/bid/26132http://www.ubuntu.com/usn/usn-536-1http://www.vupen.com/english/advisories/2007/3544http://www.vupen.com/english/advisories/2007/3545http://www.vupen.com/english/advisories/2007/3587http://www.vupen.com/english/advisories/2007/4272http://www.vupen.com/english/advisories/2008/0082http://www.vupen.com/english/advisories/2008/0083http://www.vupen.com/english/advisories/2008/0643https://bugzilla.mozilla.org/buglist.cgi?bug_id=309322%2C330563%2C341858%2C344064%2C348126%2C354645%2C361745%2C362901%2C378670%2C378682%2C379799%2C382376%2C384105%2C386382%2C386914%2C387033%2C387460%2C387844%2C391974%2C392285%2C393770%2C394014%2C394418https://exchange.xforce.ibmcloud.com/vulnerabilities/37281https://issues.rpath.com/browse/RPL-1858https://issues.rpath.com/browse/RPL-1884https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10459https://usn.ubuntu.com/535-1/https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=196481http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579http://secunia.com/advisories/27276http://secunia.com/advisories/27298http://secunia.com/advisories/27311http://secunia.com/advisories/27313http://secunia.com/advisories/27315http://secunia.com/advisories/27325http://secunia.com/advisories/27326http://secunia.com/advisories/27327http://secunia.com/advisories/27335http://secunia.com/advisories/27336http://secunia.com/advisories/27356http://secunia.com/advisories/27360http://secunia.com/advisories/27383http://secunia.com/advisories/27387http://secunia.com/advisories/27403http://secunia.com/advisories/27414http://secunia.com/advisories/27425http://secunia.com/advisories/27480http://secunia.com/advisories/27665http://secunia.com/advisories/27680http://secunia.com/advisories/27704http://secunia.com/advisories/27744http://secunia.com/advisories/28179http://secunia.com/advisories/28363
+ 46 more references
2007-10-21
Published