CVE-2007-5947
Mozilla Firefox <2.0.0.10 & SeaMonkey <1.1.7 - XSS
Title source: llmDescription
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.
References (61)
... and 41 more
Scores
EPSS
0.0791
EPSS Percentile
91.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (15)
mozilla/firefox
< 2.0.0.9
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/seamonkey
< 1.1.6
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
Timeline
Published
Nov 14, 2007
Tracked Since
Feb 18, 2026