CVE-2007-1095
Last modified
CVE-2007-1095 is a vulnerability of currently unknown severity. Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.. EPSS estimates a 2.19% chance of exploitation in the next 30 days.
Description
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 2.0.0.7 |
| Mozilla | Firefox | 0.1 |
| Mozilla | Firefox | 0.2 |
| Mozilla | Firefox | 0.3 |
| Mozilla | Firefox | 0.4 |
| Mozilla | Firefox | 0.5 |
| Mozilla | Firefox | 0.6 |
| Mozilla | Firefox | 0.6.1 |
| Mozilla | Firefox | 0.7 |
| Mozilla | Firefox | 0.7.1 |
| Mozilla | Firefox | 0.8 |
| Mozilla | Firefox | 0.9 |
| Mozilla | Firefox | 0.9.1 |
| Mozilla | Firefox | 0.9.2 |
| Mozilla | Firefox | 0.9.3 |
| Mozilla | Firefox | 0.10 |
| Mozilla | Firefox | 0.10.1 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.4.1 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.0.9 |
| Mozilla | Firefox | 1.5.0.10 |
| Mozilla | Firefox | 1.5.0.11 |
| Mozilla | Firefox | 1.5.0.12 |
| Mozilla | Firefox | 1.5.1 |
| Mozilla | Firefox | 1.5.2 |
| Mozilla | Firefox | 1.5.3 |
| Mozilla | Firefox | 1.5.4 |
| Mozilla | Firefox | 1.5.5 |
| Mozilla | Firefox | 1.5.6 |
| Mozilla | Firefox | 1.5.7 |
| Mozilla | Firefox | 1.5.8 |
| Mozilla | Firefox | 1.8 |
| Mozilla | Firefox | 2.0 |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/27276Vendor Advisory
- http://secunia.com/advisories/27298Vendor Advisory
- http://secunia.com/advisories/27311Vendor Advisory
- http://secunia.com/advisories/27315Vendor Advisory
- http://secunia.com/advisories/27325Vendor Advisory
- http://secunia.com/advisories/27327Vendor Advisory
- http://secunia.com/advisories/27335Vendor Advisory
- http://secunia.com/advisories/27336Vendor Advisory
- http://secunia.com/advisories/27356Vendor Advisory
- http://secunia.com/advisories/27360Vendor Advisory
- http://secunia.com/advisories/27383Vendor Advisory
- http://secunia.com/advisories/27387Vendor Advisory
- http://secunia.com/advisories/27403Vendor Advisory
- http://secunia.com/advisories/27414Vendor Advisory
- http://secunia.com/advisories/27425Vendor Advisory
- http://secunia.com/advisories/27480Vendor Advisory
- http://secunia.com/advisories/27665Vendor Advisory
- http://secunia.com/advisories/27680Vendor Advisory
- http://secunia.com/advisories/28398Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0979.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0980.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0981.htmlVendor Advisory
- http://secunia.com/advisories/27276Vendor Advisory
- http://secunia.com/advisories/27298Vendor Advisory
- http://secunia.com/advisories/27311Vendor Advisory
- http://secunia.com/advisories/27315Vendor Advisory
- http://secunia.com/advisories/27325Vendor Advisory
- http://secunia.com/advisories/27327Vendor Advisory
- http://secunia.com/advisories/27335Vendor Advisory
- http://secunia.com/advisories/27336Vendor Advisory
- http://secunia.com/advisories/27356Vendor Advisory
- http://secunia.com/advisories/27360Vendor Advisory
- http://secunia.com/advisories/27383Vendor Advisory
- http://secunia.com/advisories/27387Vendor Advisory
- http://secunia.com/advisories/27403Vendor Advisory
- http://secunia.com/advisories/27414Vendor Advisory
- http://secunia.com/advisories/27425Vendor Advisory
- http://secunia.com/advisories/27480Vendor Advisory
- http://secunia.com/advisories/27665Vendor Advisory
- http://secunia.com/advisories/27680Vendor Advisory
- http://secunia.com/advisories/28398Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0979.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0980.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0981.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1095?
How severe is CVE-2007-1095?
How do I fix CVE-2007-1095?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1089IBM DB2 Universal Database (UDB) 9.1 GA through 9.1 FP1 allo…
- CVE-2007-1090Microsoft Windows Explorer on Windows XP and 2003 allows rem…
- CVE-2007-1091Microsoft Internet Explorer 7 allows remote attackers to pre…
- CVE-2007-1092Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.…
- CVE-2007-1093Multiple unspecified vulnerabilities in JP1/Cm2/Network Node…
- CVE-2007-1094Microsoft Internet Explorer 7 allows remote attackers to cau…
- CVE-2007-1096Cross-site scripting (XSS) vulnerability in ps_cart.php in V…
- CVE-2007-1097Unrestricted file upload vulnerability in the onAttachFiles …
- CVE-2007-1098Multiple unspecified vulnerabilities in ScryMUD before 2.1.1…
- CVE-2007-1099dbclient in Dropbear SSH client before 0.49 does not suffici…
- CVE-2007-1100Directory traversal vulnerability in download.php in Ahmet S…
- CVE-2007-1101Multiple cross-site scripting (XSS) vulnerabilities in Photo…
Are you affected by CVE-2007-1095?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
