Vulnerability Description
Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocked popup.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 1.5.0.9 |
References
- ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc
- ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc
- http://fedoranews.org/cms/node/2713
- http://fedoranews.org/cms/node/2728
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052209.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052211.html
- http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html
- http://rhn.redhat.com/errata/RHSA-2007-0077.html
- http://secunia.com/advisories/24205
- http://secunia.com/advisories/24238
- http://secunia.com/advisories/24287
- http://secunia.com/advisories/24290
- http://secunia.com/advisories/24293
- http://secunia.com/advisories/24320
FAQ
What is CVE-2007-0800?
CVE-2007-0800 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary ...
How severe is CVE-2007-0800?
CVE-2007-0800 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-0800?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.