CVE-2007-5960
Summary
| CVE | CVE-2007-5960 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-11-26 23:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer headers and bypass Referer-based CSRF protection schemes by setting window.location and using a modal alert dialog that causes the wrong Referer to be sent. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Firefox | 0.10 | All | All | All |
| Application | Mozilla | Firefox | 0.10.1 | All | All | All |
| Application | Mozilla | Firefox | 0.8 | All | All | All |
| Application | Mozilla | Firefox | 0.9 | All | All | All |
| Application | Mozilla | Firefox | 0.9.1 | All | All | All |
| Application | Mozilla | Firefox | 0.9.2 | All | All | All |
| Application | Mozilla | Firefox | 0.9.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0 | All | All | All |
| Application | Mozilla | Firefox | 1.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.0.7 | All | All | All |
| Application | Mozilla | Firefox | 1.0.8 | All | All | All |
| Application | Mozilla | Firefox | 1.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.10 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.11 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.12 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.7 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.8 | All | All | All |
| Application | Mozilla | Firefox | 1.5.0.9 | All | All | All |
| Application | Mozilla | Firefox | 1.5.1 | All | All | All |
| Application | Mozilla | Firefox | 1.5.2 | All | All | All |
| Application | Mozilla | Firefox | 1.5.3 | All | All | All |
| Application | Mozilla | Firefox | 1.5.4 | All | All | All |
| Application | Mozilla | Firefox | 1.5.5 | All | All | All |
| Application | Mozilla | Firefox | 1.5.6 | All | All | All |
| Application | Mozilla | Firefox | 1.5.7 | All | All | All |
| Application | Mozilla | Firefox | 1.5.8 | All | All | All |
| Application | Mozilla | Firefox | 1.8 | All | All | All |
| Application | Mozilla | Firefox | 2.0 | All | All | All |
| Application | Mozilla | Firefox | 2.0 | beta1 | All | All |
| Application | Mozilla | Firefox | 2.0 | rc2 | All | All |
| Application | Mozilla | Firefox | 2.0 | rc3 | All | All |
| Application | Mozilla | Firefox | 2.0.0.1 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.2 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.3 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.4 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.5 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.6 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.7 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.8 | All | All | All |
| Application | Mozilla | Firefox | 2.0.0.9 | All | All | All |
| Application | Mozilla | Seamonkey | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Announcement: Mozilla Firefox 2.0.0.10 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Mozilla Firefox Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories:rPSA-2008-0093 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| [SECURITY] Fedora Core 6 Update: firefox-1.5.0.12-7.fc6 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Advisories:rPSA-2007-0260 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Netscape Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| issues.rpath.com/browse/RPL-1984 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Debian update for xulrunner - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| Mozilla Firefox and SeaMonkey Windows.Location Property HTTP Referer Header Spoofing Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Yahoo | af854a3a-2127-422b-91ae-364da2661108 | browser.netscape.com | |
| issues.rpath.com/browse/RPL-1995 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| MFSA 2007-39: Referer-spoofing via window.location race condition | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| 200909 – (CVE-2007-5947) www-client/seamonkey (bin) < 1.1.7 Multiple vulnerabilities (CVE-2007-{5947,5959,5960}) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| SeaMonkey Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| Gentoo update for mozilla-firefox/-bin and seamonkey/-bin - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [SECURITY] Fedora 7 Update: firefox-2.0.0.10-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Gentoo Bug 198965 - www-client/mozilla-firefox < 2.0.0.11 Multiple vulnerabilities (CVE-2007-{5947,5959,5960}) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| Mandriva update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| The Slackware Linux Project: Slackware Security Advisories | af854a3a-2127-422b-91ae-364da2661108 | slackware.com | |
| Red Hat update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Fedora update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| HPSBUX02153 SSRT061181 rev.7 - HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) - c00771742 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| Fedora update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Slackware update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rPath update for thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SUSE update for MozillaFirefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Vendor Advisory |
| Advisories:rPSA-2008-0093 - rPath Wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Debian -- Security Information -- DSA-1424-1 iceweasel | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Support / Security / Advisories / / MDKSA-2007:246 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Red Hat update for thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Slackware update for seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Gentoo Linux Documentation -- Mozilla Firefox, SeaMonkey: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| HP-UX update for Firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-546-1: Firefox vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| [SECURITY] Fedora 8 Update: seamonkey-1.1.7-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Ubuntu update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mozilla Firefox Referer Header Spoofing Bug Permits Cross-Site Request Forgery Attacks | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Debian -- Security Information -- DSA-1425-1 xulrunner | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| rPath update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for iceweasel - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-546-2: Firefox regression | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [SECURITY] Fedora 7 Update: seamonkey-1.1.7-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| access.redhat.com | CVE-2007-5960 | MITRE | access.redhat.com | |
| 394261 – (CVE-2007-5960) CVE-2007-5960 Mozilla Cross-site Request Forgery flaw | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.