CVE-2007-0780

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/02/2007
Last modified:
09/04/2025

Description

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1.5 (including) 1.5.0.10 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 2.0 (including) 2.0.0.2 (excluding)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 1.0.8 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools