Lucene search

K
ubuntucveUbuntu.comUB:CVE-2007-3656
HistoryJul 10, 2007 - 12:00 a.m.

CVE-2007-3656

2007-07-1000:00:00
ubuntu.com
ubuntu.com
19

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.921

Percentile

99.0%

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform
a security zone check when processing a wyciwyg URI, which allows remote
attackers to obtain sensitive information, poison the browser cache, and
possibly enable further attack vectors via (1) HTTP 302 redirect controls,
(2) XMLHttpRequest, or (3) view-source URIs.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchfirefox< 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1UNKNOWN
ubuntu6.10noarchfirefox< 2.0.0.6+0dfsg-0ubuntu0.6.10UNKNOWN
ubuntu7.04noarchfirefox< 2.0.0.6+1-0ubuntu1UNKNOWN

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.921

Percentile

99.0%