[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-3844Date: (C)2007-08-07   (M)2023-12-22


Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1018479
SECTRACK-1018480
SECTRACK-1018481
SUNALERT-103177
http://www.securityfocus.com/archive/1/475265/100/200/threaded
http://www.securityfocus.com/archive/1/475450/30/5550/threaded
SUNALERT-201516
BID-25142
SECUNIA-26234
SECUNIA-26258
SECUNIA-26288
SECUNIA-26303
SECUNIA-26309
SECUNIA-26331
SECUNIA-26335
SECUNIA-26393
SECUNIA-26460
SECUNIA-26572
SECUNIA-27276
SECUNIA-27298
SECUNIA-27325
SECUNIA-27326
SECUNIA-27327
SECUNIA-27356
SECUNIA-27414
SECUNIA-27680
SECUNIA-28135
SECUNIA-28363
ADV-2007-3587
ADV-2007-4256
ADV-2008-0082
DSA-1344
DSA-1345
DSA-1346
DSA-1391
FEDORA-2007-2601
FEDORA-2007-3431
GLSA-200708-09
HPSBUX02153
HPSBUX02156
MDKSA-2007:152
MDVSA-2007:047
MDVSA-2008:047
RHSA-2007:0979
RHSA-2007:0980
RHSA-2007:0981
SSA:2007-213-01
SUSE-SA:2007:057
USN-493-1
USN-503-1
http://bugzilla.mozilla.org/show_bug.cgi?id=388121
http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html
http://www.mozilla.org/security/announce/2007/mfsa2007-26.html
https://issues.rpath.com/browse/RPL-1600
oval:org.mitre.oval:def:9493

CPE    3
cpe:/a:mozilla:firefox:2.0.0.5
cpe:/a:mozilla:seamonkey:1.1.3
cpe:/a:mozilla:thunderbird:2.0.0.5

© SecPod Technologies