Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site that is visited by a client.
References
Link Providers
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 cve-icon cve-icon
http://lcamtuf.coredump.cx/ietrap/ff/ cve-icon cve-icon
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052630.html cve-icon cve-icon
http://osvdb.org/33809 cve-icon cve-icon
http://secunia.com/advisories/27276 cve-icon cve-icon
http://secunia.com/advisories/27298 cve-icon cve-icon
http://secunia.com/advisories/27311 cve-icon cve-icon
http://secunia.com/advisories/27315 cve-icon cve-icon
http://secunia.com/advisories/27325 cve-icon cve-icon
http://secunia.com/advisories/27327 cve-icon cve-icon
http://secunia.com/advisories/27335 cve-icon cve-icon
http://secunia.com/advisories/27336 cve-icon cve-icon
http://secunia.com/advisories/27356 cve-icon cve-icon
http://secunia.com/advisories/27360 cve-icon cve-icon
http://secunia.com/advisories/27383 cve-icon cve-icon
http://secunia.com/advisories/27387 cve-icon cve-icon
http://secunia.com/advisories/27403 cve-icon cve-icon
http://secunia.com/advisories/27414 cve-icon cve-icon
http://secunia.com/advisories/27425 cve-icon cve-icon
http://secunia.com/advisories/27480 cve-icon cve-icon
http://secunia.com/advisories/27665 cve-icon cve-icon
http://secunia.com/advisories/27680 cve-icon cve-icon
http://secunia.com/advisories/28398 cve-icon cve-icon
http://securityreason.com/securityalert/2310 cve-icon cve-icon
http://securitytracker.com/id?1018837 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1 cve-icon cve-icon
http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1392 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1396 cve-icon cve-icon
http://www.debian.org/security/2007/dsa-1401 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml cve-icon cve-icon
http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202 cve-icon cve-icon
http://www.mozilla.org/security/announce/2007/mfsa2007-30.html cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_57_mozilla.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0979.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0980.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0981.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/461007/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/461023/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482876/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482925/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/482932/100/200/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/22688 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-536-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3544 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3587 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0083 cve-icon cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=371360 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/32647 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/32649 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1858 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-1095 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11665 cve-icon cve-icon
https://usn.ubuntu.com/535-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-1095 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-02-26T17:00:00

Updated: 2024-08-07T12:43:22.516Z

Reserved: 2007-02-26T00:00:00

Link: CVE-2007-1095

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-02-26T17:28:00.000

Modified: 2018-10-16T16:36:39.577

Link: CVE-2007-1095

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-02-23T00:00:00Z

Links: CVE-2007-1095 - Bugzilla