CVE-2007-0994
Last modified
CVE-2007-0994 is a vulnerability of currently unknown severity. A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.. EPSS estimates a 3.21% chance of exploitation in the next 30 days.
Description
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 1.5, < 1.5.0.10 |
| Mozilla | Firefox | >= 2.0, < 2.0.0.2 |
| Mozilla | Seamonkey | >= 1.0, < 1.0.8 |
| Mozilla | Seamonkey | >= 1.1, < 1.1.1 |
| Debian | Debian Linux | 3.1 |
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733Exploit, Issue Tracking, Patch, Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://securitytracker.com/id?1017726Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.securityfocus.com/bid/22826Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/0823Third Party Advisory
- https://issues.rpath.com/browse/RPL-1103Broken Link
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733Exploit, Issue Tracking, Patch, Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://securitytracker.com/id?1017726Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.securityfocus.com/bid/22826Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/0823Third Party Advisory
- https://issues.rpath.com/browse/RPL-1103Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0994?
How severe is CVE-2007-0994?
How do I fix CVE-2007-0994?
Are you affected by CVE-2007-0994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
