CVE-2007-3089

Firefox < 2.0.0.5 - Arbitrary HTML Display and JavaScript Execution via IFRAME document.write

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

References (52)

Core 52
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-490-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018412
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26107
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/143297
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26179
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/4256
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25589
Various Sources x_refsource_misc
http://lcamtuf.coredump.cx/ifsnatch/
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:152
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200708-09.xml
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1339
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11122
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-199A.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26151
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34701
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28135
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/470446/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26216
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26103
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24286
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26072
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26149
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2564
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1337
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26211
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2781
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26159
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_49_mozilla.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1338
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=381300
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26095
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/474542/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26258
Issue Tracking x_refsource_confirm
https://bugzilla.mozilla.org/show_bug.cgi?id=382686
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26460
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26106
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.asc
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0724.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/474226/100/0/threaded
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0723.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26271
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38024
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2007-0722.html
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26204
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26205

Scores

EPSS 0.0277
EPSS Percentile 84.8%

Details

Status published
Products (41)
mozilla/firefox 0.8
mozilla/firefox 0.9
mozilla/firefox 0.9.1
mozilla/firefox 0.9.2
mozilla/firefox 0.9.3
mozilla/firefox 0.10
mozilla/firefox 0.10.1
mozilla/firefox 1.0
mozilla/firefox 1.0.1
mozilla/firefox 1.0.2
... and 31 more
Published Jun 06, 2007
Tracked Since Feb 18, 2026