Lucene search

K
cveRedhatCVE-2007-0994
HistoryMar 06, 2007 - 12:19 a.m.

CVE-2007-0994

2007-03-0600:19:00
CWE-94
redhat
web.nvd.nist.gov
57
2
cve-2007-0994
mozilla firefox
seamonkey
regression error
remote attackers
arbitrary javascript
html mail message
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.03

Percentile

91.1%

A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.

Affected configurations

Nvd
Node
mozillafirefoxRange1.51.5.0.10
OR
mozillafirefoxRange2.02.0.0.2
OR
mozillaseamonkeyRange1.01.0.8
OR
mozillaseamonkeyRange1.11.1.1
Node
debiandebian_linuxMatch3.1
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
mozillaseamonkey*cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
debiandebian_linux3.1cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*

References

Social References

More

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.03

Percentile

91.1%