[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-3656Date: (C)2007-07-10   (M)2023-12-22


Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1018411
SUNALERT-103177
20070701-01-P
http://www.securityfocus.com/archive/1/473191/100/0/threaded
http://www.securityfocus.com/archive/1/474226/100/0/threaded
http://www.securityfocus.com/archive/1/474542/100/0/threaded
SUNALERT-201516
BID-24831
SECUNIA-25589
SECUNIA-25990
SECUNIA-26072
SECUNIA-26103
SECUNIA-26107
SECUNIA-26149
SECUNIA-26151
SECUNIA-26159
SECUNIA-26179
SECUNIA-26204
SECUNIA-26205
SECUNIA-26211
SECUNIA-26216
SECUNIA-26258
SECUNIA-26271
SECUNIA-26460
SECUNIA-28135
SREASON-2872
OSVDB-38028
ADV-2007-4256
DSA-1337
DSA-1338
DSA-1339
GLSA-200708-09
HPSBUX02153
MDKSA-2007:152
RHSA-2007:0722
RHSA-2007:0724
SUSE-SA:2007:049
USN-490-1
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt
http://lcamtuf.coredump.cx/ffcache/
http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html
http://www.mozilla.org/security/announce/2007/mfsa2007-24.html
https://bugzilla.mozilla.org/show_bug.cgi?id=387333
mozilla-wyciwyg-security-bypass(35298)
oval:org.mitre.oval:def:9105

CPE    31
cpe:/a:mozilla:firefox:1.5.0.10
cpe:/a:mozilla:firefox:1.5.0.11
cpe:/a:mozilla:firefox:1.5.0.12
cpe:/a:mozilla:firefox:1.5.0.4
...
CWE    1
CWE-200

© SecPod Technologies