CVE-2007-3089
Firefox < 2.0.0.5 - Arbitrary HTML Display and JavaScript Execution via IFRAME document.write
Title source: llmDescription
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.
References (52)
Core 52
Core References
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-490-1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1018412
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26107
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/143297
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26179
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4256
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/25589
Various Sources x_refsource_misc
http://lcamtuf.coredump.cx/ifsnatch/
Vendor Advisory vendor-advisory
x_refsource_hp
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:152
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200708-09.xml
Various Sources x_refsource_confirm
http://www.mozilla.org/security/announce/2007/mfsa2007-20.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2007/dsa-1339
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11122
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-199A.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26151
Third Party Advisory mailing-list
x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34701
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/28135
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/470446/100/0/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26216
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26103
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/24286
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26072
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26149
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2564
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2007/dsa-1337
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26211
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/2781
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26159
Vendor Advisory vendor-advisory
x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_49_mozilla.html
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2007/dsa-1338
Vendor Advisory x_refsource_confirm
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=381300
Vendor Advisory x_refsource_confirm
http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26095
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/474542/100/0/threaded
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26258
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=382686
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26460
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26106
Vendor Advisory vendor-advisory
x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.asc
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0724.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/474226/100/0/threaded
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0723.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26271
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/38024
Vendor Advisory vendor-advisory
x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0722.html
Vendor Advisory vendor-advisory
x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26204
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/26205
Scores
EPSS
0.0277
EPSS Percentile
84.8%
Details
Status
published
Products (41)
mozilla/firefox
0.8
mozilla/firefox
0.9
mozilla/firefox
0.9.1
mozilla/firefox
0.9.2
mozilla/firefox
0.9.3
mozilla/firefox
0.10
mozilla/firefox
0.10.1
mozilla/firefox
1.0
mozilla/firefox
1.0.1
mozilla/firefox
1.0.2
... and 31 more
Published
Jun 06, 2007
Tracked Since
Feb 18, 2026