Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-0994
HistoryMar 06, 2007 - 12:00 a.m.

CVE-2007-0994

2007-03-0600:00:00
ubuntu.com
ubuntu.com
19

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.03

Percentile

91.1%

A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before
1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows
remote attackers to execute arbitrary JavaScript as the user via an HTML
mail message with a javascript: URI in an (1) img, (2) link, or (3) style
tag, which bypasses the access checks and executes code with chrome
privileges.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1UNKNOWN
ubuntu6.10noarchfirefox< 2.0.0.6+0dfsg-0ubuntu0.6.10UNKNOWN
ubuntu7.04noarchfirefox< 2.0.0.6+1-0ubuntu1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.03

Percentile

91.1%