CVE-2007-0994
Last modified
CVE-2007-0994 is a vulnerability of currently unknown severity. A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.. EPSS estimates a 3.21% chance of exploitation in the next 30 days.
Description
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 1.5, < 1.5.0.10 |
| Mozilla | Firefox | >= 2.0, < 2.0.0.2 |
| Mozilla | Seamonkey | >= 1.0, < 1.0.8 |
| Mozilla | Seamonkey | >= 1.1, < 1.1.1 |
| Debian | Debian Linux | 3.1 |
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733Exploit, Issue Tracking, Patch, Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://securitytracker.com/id?1017726Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.securityfocus.com/bid/22826Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/0823Third Party Advisory
- https://issues.rpath.com/browse/RPL-1103Broken Link
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=230733Exploit, Issue Tracking, Patch, Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://securitytracker.com/id?1017726Third Party Advisory, VDB Entry
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.securityfocus.com/bid/22826Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/0823Third Party Advisory
- https://issues.rpath.com/browse/RPL-1103Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0994?
How severe is CVE-2007-0994?
How do I fix CVE-2007-0994?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0988The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 …
- CVE-2007-0989Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-0990Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-0991Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-0992Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2007-0993Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-0995Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and …
- CVE-2007-0996The child frames in Mozilla Firefox before 1.5.0.10 and 2.x …
- CVE-2007-0997Race condition in the tee (sys_tee) system call in the Linux…
- CVE-2007-0998The VNC server implementation in QEMU, as used by Xen and po…
- CVE-2007-0999Format string vulnerability in Ekiga 2.0.3, and probably oth…
- CVE-2007-1000The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglu…
Are you affected by CVE-2007-0994?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
