6.8
CVSSv2

CVE-2007-0994

Published: 06/03/2007 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A regression error in Mozilla Firefox 2.x prior to 2.0.0.2 and 1.x prior to 1.5.0.10, and SeaMonkey 1.1 prior to 1.1.1 and 1.0 prior to 1.0.8, allows remote malicious users to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla seamonkey

mozilla firefox

debian debian linux 3.1

Vendor Advisories

Several remote vulnerabilities have been discovered in Mozilla Firefox This will be the last security update of Mozilla-based products for the oldstable (sarge) distribution of Debian We recommend to upgrade to stable (etch) as soon as possible The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CVE-2007-1 ...
Mozilla Foundation Security Advisory 2007-09 Privilege escalation by setting imgsrc to javascript: URI Announced March 5, 2007 Reporter moz_bug_r_a4 Impact Critical Products Firefox, SeaMonkey Fixed in ...