First published: Mon Feb 26 2007(Updated: )
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <=2.0.0.7 | |
Firefox | =0.1 | |
Firefox | =0.2 | |
Firefox | =0.3 | |
Firefox | =0.4 | |
Firefox | =0.5 | |
Firefox | =0.6 | |
Firefox | =0.6.1 | |
Firefox | =0.7 | |
Firefox | =0.7.1 | |
Firefox | =0.8 | |
Firefox | =0.9 | |
Firefox | =0.9-rc | |
Firefox | =0.9.1 | |
Firefox | =0.9.2 | |
Firefox | =0.9.3 | |
Firefox | =0.10 | |
Firefox | =0.10.1 | |
Firefox | =1.0 | |
Firefox | =1.0-preview_release | |
Firefox | =1.0.1 | |
Firefox | =1.0.2 | |
Firefox | =1.0.3 | |
Firefox | =1.0.4 | |
Firefox | =1.0.5 | |
Firefox | =1.0.6 | |
Firefox | =1.0.7 | |
Firefox | =1.0.8 | |
Firefox | =1.4.1 | |
Firefox | =1.5 | |
Firefox | =1.5-beta1 | |
Firefox | =1.5-beta2 | |
Firefox | =1.5.0.1 | |
Firefox | =1.5.0.2 | |
Firefox | =1.5.0.3 | |
Firefox | =1.5.0.4 | |
Firefox | =1.5.0.5 | |
Firefox | =1.5.0.6 | |
Firefox | =1.5.0.7 | |
Firefox | =1.5.0.8 | |
Firefox | =1.5.0.9 | |
Firefox | =1.5.0.10 | |
Firefox | =1.5.0.11 | |
Firefox | =1.5.0.12 | |
Firefox | =1.5.1 | |
Firefox | =1.5.2 | |
Firefox | =1.5.3 | |
Firefox | =1.5.4 | |
Firefox | =1.5.5 | |
Firefox | =1.5.6 | |
Firefox | =1.5.7 | |
Firefox | =1.5.8 | |
Firefox | =1.8 | |
Firefox | =2.0 | |
Firefox | =2.0.0.1 | |
Firefox | =2.0.0.2 | |
Firefox | =2.0.0.3 | |
Firefox | =2.0.0.4 | |
Firefox | =2.0.0.5 | |
Firefox | =2.0.0.6 | |
Mozilla SeaMonkey | <=1.1.4 | |
Mozilla SeaMonkey | =1.0 | |
Mozilla SeaMonkey | =1.0.1 | |
Mozilla SeaMonkey | =1.0.2 | |
Mozilla SeaMonkey | =1.0.3 | |
Mozilla SeaMonkey | =1.0.4 | |
Mozilla SeaMonkey | =1.0.5 | |
Mozilla SeaMonkey | =1.0.6 | |
Mozilla SeaMonkey | =1.0.7 | |
Mozilla SeaMonkey | =1.0.8 | |
Mozilla SeaMonkey | =1.0.9 | |
Mozilla SeaMonkey | =1.1 | |
Mozilla SeaMonkey | =1.1.1 | |
Mozilla SeaMonkey | =1.1.2 | |
Mozilla SeaMonkey | =1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1095 is classified as a high severity vulnerability due to the potential for executing malicious JavaScript code.
To fix CVE-2007-1095, update Mozilla Firefox or SeaMonkey to version 2.0.0.8 or later.
CVE-2007-1095 affects all Firefox versions prior to 2.0.0.8.
CVE-2007-1095 affects all SeaMonkey versions prior to 1.1.5.
CVE-2007-1095 can be exploited to run JavaScript code unauthorizedly and access the location DOM of the user's browser.