CVE-2007-5947

Mozilla Firefox <2.0.0.10 & SeaMonkey <1.1.7 - XSS

Title source: llm

Description

The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.

Scores

EPSS 0.0791
EPSS Percentile 91.9%

Classification

CWE
CWE-79
Status draft

Affected Products (15)

mozilla/firefox < 2.0.0.9
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/seamonkey < 1.1.6
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey
mozilla/seamonkey

Timeline

Published Nov 14, 2007
Tracked Since Feb 18, 2026