CVE-2007-5960
published 2007-11-26CVE-2007-5960: Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.47%
70.8th percentile
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9vw2-7m33-r6hw: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01
CVE-2007-5960 [MEDIUM] CWE-22 GHSA-9vw2-7m33-r6hw: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.
Ubuntu
Firefox regression
vendor_ubuntu·2007-12-04·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: Firefox regression
USN-546-1 fixed vulnerabilities in Firefox. The upstream update included
a faulty patch which caused the drawImage method of the canvas element to
fail. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Firefox incorrectly associated redirected sites
as the origin of "jar:" contents. A malicious web site could exploit this
to modify or steal confidential data (such as passwords) from other web
sites. (CVE-2007-5947)
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5959)
Gregory Fleischer discovered that it was poss
Red Hat
Mozilla Cross-site Request Forgery flaw
vendor_redhat·2007-11-26·CVSS 4.3
CVE-2007-5960 [MEDIUM] CWE-352 Mozilla Cross-site Request Forgery flaw
Mozilla Cross-site Request Forgery flaw
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-11-26·CVSS 4.3
CVE-2007-5959 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
It was discovered that Firefox incorrectly associated redirected sites
as the origin of "jar:" contents. A malicious web site could exploit this
to modify or steal confidential data (such as passwords) from other web
sites. (CVE-2007-5947)
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-5959)
Gregory Fleischer discovered that it was possible to use JavaScript to
manipulate Firefox's Referer header. A malicious web site could exploit
this to conduct cross-site request forgeries against sites that relied
only on Referer headers for protection from such attacks. (CVE-2007-596
No detection rules found.
No public exploits indexed.
http://browser.netscape.com/releasenotes/http://bugs.gentoo.org/show_bug.cgi?id=198965http://bugs.gentoo.org/show_bug.cgi?id=200909http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00004.htmlhttp://secunia.com/advisories/27725http://secunia.com/advisories/27793http://secunia.com/advisories/27796http://secunia.com/advisories/27797http://secunia.com/advisories/27800http://secunia.com/advisories/27816http://secunia.com/advisories/27838http://secunia.com/advisories/27845http://secunia.com/advisories/27855http://secunia.com/advisories/27944http://secunia.com/advisories/27955http://secunia.com/advisories/27957http://secunia.com/advisories/27979http://secunia.com/advisories/28001http://secunia.com/advisories/28016http://secunia.com/advisories/28171http://secunia.com/advisories/28277http://secunia.com/advisories/28398http://secunia.com/advisories/29164http://security.gentoo.org/glsa/glsa-200712-21.xmlhttp://securitytracker.com/id?1018995http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.365006http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374833http://sunsolve.sun.com/search/document.do?assetkey=1-26-231441-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018977.1-1http://wiki.rpath.com/Advisories:rPSA-2008-0093http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0260http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093http://www.debian.org/security/2007/dsa-1424http://www.debian.org/security/2007/dsa-1425http://www.mandriva.com/security/advisories?name=MDKSA-2007:246http://www.mozilla.org/security/announce/2007/mfsa2007-39.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1082.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1083.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1084.htmlhttp://www.securityfocus.com/archive/1/488002/100/0/threadedhttp://www.securityfocus.com/archive/1/488971/100/0/threadedhttp://www.securityfocus.com/bid/26589http://www.ubuntu.com/usn/usn-546-2http://www.vupen.com/english/advisories/2007/4002http://www.vupen.com/english/advisories/2007/4018http://www.vupen.com/english/advisories/2008/0083http://www.vupen.com/english/advisories/2008/0643https://exchange.xforce.ibmcloud.com/vulnerabilities/38644https://issues.rpath.com/browse/RPL-1984https://issues.rpath.com/browse/RPL-1995https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9794https://usn.ubuntu.com/546-1/https://www.redhat.com/archives/fedora-package-announce/2007-December/msg00115.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00135.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-December/msg00168.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-November/msg01011.htmlhttp://browser.netscape.com/releasenotes/http://bugs.gentoo.org/show_bug.cgi?id=198965http://bugs.gentoo.org/show_bug.cgi?id=200909http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://lists.opensuse.org/opensuse-security-announce/2007-12/msg00004.htmlhttp://secunia.com/advisories/27725http://secunia.com/advisories/27793http://secunia.com/advisories/27796http://secunia.com/advisories/27797http://secunia.com/advisories/27800http://secunia.com/advisories/27816http://secunia.com/advisories/27838http://secunia.com/advisories/27845http://secunia.com/advisories/27855http://secunia.com/advisories/27944http://secunia.com/advisories/27955http://secunia.com/advisories/27957http://secunia.com/advisories/27979http://secunia.com/advisories/28001http://secunia.com/advisories/28016http://secunia.com/advisories/28171http://secunia.com/advisories/28277http://secunia.com/advisories/28398http://secunia.com/advisories/29164http://security.gentoo.org/glsa/glsa-200712-21.xmlhttp://securitytracker.com/id?1018995http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.365006http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374833http://sunsolve.sun.com/search/document.do?assetkey=1-26-231441-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1018977.1-1http://wiki.rpath.com/Advisories:rPSA-2008-0093http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0260http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0093http://www.debian.org/security/2007/dsa-1424http://www.debian.org/security/2007/dsa-1425http://www.mandriva.com/security/advisories?name=MDKSA-2007:246http://www.mozilla.org/security/announce/2007/mfsa2007-39.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1082.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1083.htmlhttp://www.redhat.com/support/errata/RHSA-2007-1084.htmlhttp://www.securityfocus.com/archive/1/488002/100/0/threadedhttp://www.securityfocus.com/archive/1/488971/100/0/threadedhttp://www.securityfocus.com/bid/26589
+ 14 more references
2007-11-26
Published