Unrated severityNVD Advisory· Published Mar 6, 2007· Updated Apr 23, 2026
CVE-2007-0994
CVE-2007-0994
Description
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI in an (1) img, (2) link, or (3) style tag, which bypasses the access checks and executes code with chrome privileges.
Affected products
3- cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
23- bugzilla.redhat.com/bugzilla/show_bug.cginvdExploitIssue TrackingPatchThird Party Advisory
- secunia.com/advisories/24384nvdThird Party Advisory
- secunia.com/advisories/24395nvdThird Party Advisory
- secunia.com/advisories/24455nvdThird Party Advisory
- secunia.com/advisories/24457nvdThird Party Advisory
- secunia.com/advisories/24650nvdThird Party Advisory
- secunia.com/advisories/25588nvdThird Party Advisory
- securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- slackware.com/security/viewer.phpnvdMailing ListThird Party Advisory
- slackware.com/security/viewer.phpnvdMailing ListThird Party Advisory
- www.debian.org/security/2007/dsa-1336nvdThird Party Advisory
- www.mozilla.org/security/announce/2007/mfsa2007-09.htmlnvdVendor Advisory
- www.redhat.com/support/errata/RHSA-2007-0078.htmlnvdThird Party Advisory
- www.redhat.com/support/errata/RHSA-2007-0097.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/22826nvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2007/0823nvdThird Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9749nvdThird Party Advisory
- patches.sgi.com/support/free/security/advisories/20070202-01-P.ascnvdBroken Link
- patches.sgi.com/support/free/security/advisories/20070301-01-P.ascnvdBroken Link
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvdBroken Link
- lists.suse.com/archive/suse-security-announce/2007-Mar/0001.htmlnvdBroken Link
- www.novell.com/linux/security/advisories/2007_22_mozilla.htmlnvdBroken Link
- issues.rpath.com/browse/RPL-1103nvdBroken Link
News mentions
0No linked articles in our index yet.