CVE-2007-3089
Summary
| CVE | CVE-2007-3089 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-06-06 21:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 0.10 | All | All | All |
| Application | Mozilla | Firefox | 0.10.1 | All | All | All |
| Application | Mozilla | Firefox | 0.8 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | All | All | All |
| Application | Mozilla | Firefox | 0.9.1 | All | All | All |
| Application | Mozilla | Firefox | 0.9.2 | All | All | All |
| Application | Mozilla | Firefox | 0.9.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0 | All | All | All |
| Application | Mozilla | Firefox | 1.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.0.7 | All | All | All |
| Application | Mozilla | Firefox | 1.0.8 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.10 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.11 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.7 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.8 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.9 | All | All | All |
| Application | Mozilla | Firefox | 1.5.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.7 | All | All | All |
| Application | Mozilla | Firefox | 1.5.8 | All | All | All |
| Application | Mozilla | Firefox | 2.0 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.1 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.2 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.3 | All | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla products: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| #201516: Multiple Security Vulnerabilities in Firefox and Thunderbird for Solaris 10 May Allow Execution of Arbitrary Code and Access to Unauthorized Data | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Debian update for xulrunner - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for iceweasel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityTracker.com Archives - Mozilla Firefox Lets Remote Users Inject Arbitrary Content into 'about:blank' Windows | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Slackware update for thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security update for MozillaFirefox | af854a3a-2127-422b-91ae-364da2661108 | support.novell.com | |
| #201516: Multiple Security Vulnerabilities in Firefox and Thunderbird for Solaris 10 May Allow Execution of Arbitrary Code and Access to Unauthorized Data | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| SUSE update for MozillaFirefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1337-1 xulrunner | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian update for iceape - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityReason - Assorted browser vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| rPath update for firefox and thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA07-199A -- Mozilla Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.slackware.com | |
| US-CERT Vulnerability Note VU#143297 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| SGI Advanced Linux Environment Multiple Updates - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| HPSBUX02153 SSRT061181 rev.7 - HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) - c00771742 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| Debian -- Security Information -- DSA-1339-1 iceape | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| patches.sgi.com/support/free/security/advisories/20070701-01-P.asc | af854a3a-2127-422b-91ae-364da2661108 | patches.sgi.com | |
| Mandriva update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat update for thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| MFSA 2007-20: Frame spoofing while window is loading | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| Mozilla Firefox About:Blank IFrame Cross Domain Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Gentoo update for Mozilla Products - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| wrong number (404) | af854a3a-2127-422b-91ae-364da2661108 | lcamtuf.coredump.cx | |
| Slackware update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Slackware update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Sun Solaris Firefox / Thunderbird Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Bug 382686 – [mz2] iframes from other sites can be changed while pointing at about:blank | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| Bug 381300 – Frame spoofing is possible within a short time frame while the window is loading. | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| archives.neohapsis.com/archives/fulldisclosure/2007-06/0026.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| osvdb.org/38024 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Ubuntu update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-490-1: Firefox vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian -- Security Information -- DSA-1338-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.