CVE Vulnerabilities

CVE-2007-1092

Published: Feb 26, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize hook on DOM window objects.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla1.5.0.9 (including)1.5.0.9 (including)
FirefoxMozilla2.0.0.1 (including)2.0.0.1 (including)
SeamonkeyMozilla*1.0.7 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.8-0.2.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.8-0.2.el3*
Red Hat Enterprise Linux 4RedHatdevhelp-0:0.10-0.7.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.8-0.2.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.10-0.1.el4*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.10-0.1.el4*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*

References