First published: Mon Feb 26 2007(Updated: )
Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla SeaMonkey | <=1.0.7 | |
Mozilla Firefox | =1.5.0.10 | |
Mozilla Firefox | =2.0 | |
Mozilla Firefox | =2.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0995 is considered a moderate severity vulnerability as it can allow remote attackers to bypass content filters.
To fix CVE-2007-0995, users should update to the latest versions of Mozilla Firefox or SeaMonkey that address this vulnerability.
CVE-2007-0995 affects Mozilla Firefox versions prior to 1.5.0.10 and 2.x before 2.0.0.2, as well as SeaMonkey versions before 1.0.8.
CVE-2007-0995 enables attackers to exploit invalid HTML characters in attribute names to bypass content security measures.
Using versions impacted by CVE-2007-0995 is not safe, as it could leave users vulnerable to potential cross-site scripting attacks.