CVE-2007-3737: Critical severity Mozilla Firefox vulnerability
Published Jul 18, 2007
·Updated
Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."
Affected Software
5 affected components
Mozilla Firefox=2.0.0.2
Mozilla Firefox=2.0
Mozilla Firefox=2.0.0.3
Mozilla Firefox=2.0.0.4
Mozilla Firefox=2.0.0.1
Remediation
Patch Available
Event History
Jul 18, 2007
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
Who can exploit this vulnerability?
A remote attacker can exploit it without authentication. Exploitation requires calling an event handler from an unspecified element outside of a document.
2
What level of access could successful exploitation provide?
Successful exploitation can allow arbitrary code execution with Firefox chrome privileges, affecting confidentiality, integrity, and availability.
3
Which Firefox versions need remediation?
Mozilla Firefox versions before 2.0.0.5 are affected. A patch is available.