CVE-2007-0778

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
26/02/2007
Last modified:
09/04/2025

Description

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1.5 (including) 1.5.0.10 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 2.0 (including) 2.0.0.2 (excluding)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 1.0.8 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools