First published: Mon Feb 26 2007(Updated: )
GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot property with a large, transparent, custom cursor.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | =0.9_rc | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla Firefox | =0.8 | |
Mozilla Firefox | =1.5-beta2 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla Firefox | =1.5.0.6 | |
Mozilla Firefox | =1.5.0.3 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0.99 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla Firefox | =1.0.2 | |
Mozilla SeaMonkey | =1.0-beta | |
Mozilla Firefox | =1.5-beta1 | |
Mozilla Firefox | =1.5 | |
Mozilla Firefox | =0.9.1 | |
Mozilla Firefox | =1.0.4 | |
Mozilla Firefox | =1.0.7 | |
Mozilla Firefox | =0.10.1 | |
Mozilla Firefox | =1.5.6 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla Firefox | =1.0 | |
Mozilla Firefox | =1.5.0.7 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =1.0.1 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla Firefox | =1.5.0.8 | |
Mozilla Firefox | =1.5.0.9 | |
Mozilla Firefox | =1.5.0.5 | |
Mozilla Firefox | =1.5.0.2 | |
Mozilla Firefox | =1.0.3 | |
Mozilla Firefox | =0.9.3 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla Firefox | =2.0-rc2 | |
Mozilla Firefox | =2.0.0.1 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla Firefox | =0.9.2 | |
Mozilla Firefox | =2.0-beta_1 | |
Mozilla Firefox | =1.5.8 | |
Mozilla Firefox | =1.5.0.4 | |
Mozilla Firefox | =1.5.0.1 | |
Mozilla Firefox | =0.10 | |
Mozilla Firefox | =1.0.5 | |
Mozilla Firefox | =2.0-rc3 | |
Mozilla Firefox | =1.0.6 | |
Mozilla Firefox | =1.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0779 has a moderate severity rating, allowing for user interface spoofing.
To fix CVE-2007-0779, upgrade to Mozilla Firefox version 1.5.0.10 or later, or SeaMonkey version 1.0.8 or later.
CVE-2007-0779 facilitates attacks that can spoof user interface elements such as host names or security indicators.
CVE-2007-0779 affects Mozilla Firefox versions 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, as well as SeaMonkey versions before 1.0.8.
CVE-2007-0779 can be exploited by remote attackers, making it a risk for users who interact with malicious web content.