Lucene search

K
cveRedhatCVE-2007-3736
HistoryJul 18, 2007 - 5:30 p.m.

CVE-2007-3736

2007-07-1817:30:00
redhat
web.nvd.nist.gov
52
mozilla
firefox
xss
vulnerability
cve-2007-3736
nvd
security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

8

Confidence

High

EPSS

0.491

Percentile

97.5%

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script “into another site’s context” via a “timing issue” involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

Affected configurations

Nvd
Node
mozillafirefoxMatch2.0
OR
mozillafirefoxMatch2.0.0.1
OR
mozillafirefoxMatch2.0.0.2
OR
mozillafirefoxMatch2.0.0.3
OR
mozillafirefoxMatch2.0.0.4
VendorProductVersionCPE
mozillafirefox2.0.0.3cpe:/a:mozilla:firefox:2.0.0.3:::
mozillafirefox2.0.0.1cpe:/a:mozilla:firefox:2.0.0.1:::
mozillafirefox2.0.0.2cpe:/a:mozilla:firefox:2.0.0.2:::
mozillafirefox2.0cpe:/a:mozilla:firefox:2.0:::
mozillafirefox2.0.0.4cpe:/a:mozilla:firefox:2.0.0.4:::

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

8

Confidence

High

EPSS

0.491

Percentile

97.5%