CVE Database
/

CVE-2007-3844

Back to search

CVE-2007-3844

Published: Aug 8, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an about:blank document loaded by chrome via (a) the window.open function or (b) a content.location assignment, aka "Cross Context Scripting." NOTE: this issue is caused by a CVE-2007-3089 regression.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2007-2601
vendor-advisory
x_refsource_FEDORA
USN-503-1
vendor-advisory
x_refsource_UBUNTU
MDVSA-2008:047
vendor-advisory
x_refsource_MANDRIVA
ADV-2007-3587
vdb-entry
x_refsource_VUPEN
27414
third-party-advisory
x_refsource_SECUNIA
HPSBUX02156
vendor-advisory
x_refsource_HP
26393
third-party-advisory
x_refsource_SECUNIA
26303
third-party-advisory
x_refsource_SECUNIA
ADV-2007-4256
vdb-entry
x_refsource_VUPEN
26309
third-party-advisory
x_refsource_SECUNIA
HPSBUX02153
vendor-advisory
x_refsource_HP
27298
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:152
vendor-advisory
x_refsource_MANDRIVA
GLSA-200708-09
vendor-advisory
x_refsource_GENTOO
1018481
vdb-entry
x_refsource_SECTRACK
DSA-1345
vendor-advisory
x_refsource_DEBIAN
26288
third-party-advisory
x_refsource_SECUNIA
27327
third-party-advisory
x_refsource_SECUNIA
27276
third-party-advisory
x_refsource_SECUNIA
DSA-1391
vendor-advisory
x_refsource_DEBIAN
DSA-1346
vendor-advisory
x_refsource_DEBIAN
RHSA-2007:0980
vendor-advisory
x_refsource_REDHAT
SUSE-SA:2007:057
vendor-advisory
x_refsource_SUSE
MDVSA-2007:047
vendor-advisory
x_refsource_MANDRIVA
28135
third-party-advisory
x_refsource_SECUNIA
27356
third-party-advisory
x_refsource_SECUNIA
RHSA-2007:0981
vendor-advisory
x_refsource_REDHAT
25142
vdb-entry
x_refsource_BID
SSRT061236
vendor-advisory
x_refsource_HP
FEDORA-2007-3431
vendor-advisory
x_refsource_FEDORA
ADV-2008-0082
vdb-entry
x_refsource_VUPEN
103177
vendor-advisory
x_refsource_SUNALERT
USN-493-1
vendor-advisory
x_refsource_UBUNTU
26234
third-party-advisory
x_refsource_SECUNIA
SSRT061181
vendor-advisory
x_refsource_HP
DSA-1344
vendor-advisory
x_refsource_DEBIAN
1018480
vdb-entry
x_refsource_SECTRACK
27325
third-party-advisory
x_refsource_SECUNIA
RHSA-2007:0979
vendor-advisory
x_refsource_REDHAT
1018479
vdb-entry
x_refsource_SECTRACK
26258
third-party-advisory
x_refsource_SECUNIA
27326
third-party-advisory
x_refsource_SECUNIA
28363
third-party-advisory
x_refsource_SECUNIA
26331
third-party-advisory
x_refsource_SECUNIA
26460
third-party-advisory
x_refsource_SECUNIA
27680
third-party-advisory
x_refsource_SECUNIA
20070801 FLEA-2007-0039-1 firefox
mailing-list
x_refsource_BUGTRAQ
201516
vendor-advisory
x_refsource_SUNALERT
oval:org.mitre.oval:def:9493
vdb-entry
signature
x_refsource_OVAL
20070803 FLEA-2007-0040-1 thunderbird
mailing-list
x_refsource_BUGTRAQ
26335
third-party-advisory
x_refsource_SECUNIA
26572
third-party-advisory
x_refsource_SECUNIA
SSA:2007-213-01
vendor-advisory
x_refsource_SLACKWARE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now