CVE Vulnerabilities

CVE-2007-5338

Published: Oct 21, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*2.0.0.7 (including)
SeamonkeyMozilla*1.1.4 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.6.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.5.el3*
Red Hat Enterprise Linux 4RedHatfirefox-0:1.5.0.12-0.7.el4*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-6.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-0.5.el4*
Red Hat Enterprise Linux 5RedHatfirefox-0:1.5.0.12-6.el5*
Red Hat Enterprise Linux 5RedHatthunderbird-0:1.5.0.12-5.el5*
FirefoxUbuntudapper*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*
FirefoxUbuntugutsy*
FirefoxUbuntuupstream*
Mozilla-thunderbirdUbuntudapper*
Mozilla-thunderbirdUbuntuedgy*
Mozilla-thunderbirdUbuntufeisty*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuupstream*

References