CVE
- Id
- 28695
- CVE No.
- CVE-2007-5338
- Status
- Candidate
- Description
- Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome action is performed.
- Phase
- Assigned (20071010)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
299311 | 28695 | CVE-2007-5338 | BUGTRAQ:20071029 FLEA-2007-0062-1 firefox | View |
299312 | 28695 | CVE-2007-5338 | URL:http://www.securityfocus.com/archive/1/archive/1/482925/100/0/threaded | View |
299313 | 28695 | CVE-2007-5338 | BUGTRAQ:20071026 rPSA-2007-0225-1 firefox | View |
299314 | 28695 | CVE-2007-5338 | URL:http://www.securityfocus.com/archive/1/archive/1/482876/100/200/threaded | View |
299315 | 28695 | CVE-2007-5338 | BUGTRAQ:20071029 rPSA-2007-0225-2 firefox thunderbird | View |
299316 | 28695 | CVE-2007-5338 | URL:http://www.securityfocus.com/archive/1/archive/1/482932/100/200/threaded | View |
299317 | 28695 | CVE-2007-5338 | CONFIRM:http://www.mozilla.org/security/announce/2007/mfsa2007-35.html | View |
299318 | 28695 | CVE-2007-5338 | CONFIRM:https://issues.rpath.com/browse/RPL-1858 | View |
299319 | 28695 | CVE-2007-5338 | CONFIRM:http://support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.html | View |
299320 | 28695 | CVE-2007-5338 | DEBIAN:DSA-1396 | View |
299321 | 28695 | CVE-2007-5338 | URL:http://www.debian.org/security/2007/dsa-1396 | View |
299322 | 28695 | CVE-2007-5338 | DEBIAN:DSA-1401 | View |
299323 | 28695 | CVE-2007-5338 | URL:http://www.debian.org/security/2007/dsa-1401 | View |
299324 | 28695 | CVE-2007-5338 | DEBIAN:DSA-1392 | View |
299325 | 28695 | CVE-2007-5338 | URL:http://www.debian.org/security/2007/dsa-1392 | View |
299326 | 28695 | CVE-2007-5338 | FEDORA:FEDORA-2007-2601 | View |
299327 | 28695 | CVE-2007-5338 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.html | View |
299328 | 28695 | CVE-2007-5338 | FEDORA:FEDORA-2007-2664 | View |
299329 | 28695 | CVE-2007-5338 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.html | View |
299330 | 28695 | CVE-2007-5338 | FEDORA:FEDORA-2007-3431 | View |
299331 | 28695 | CVE-2007-5338 | URL:https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.html | View |
299332 | 28695 | CVE-2007-5338 | GENTOO:GLSA-200711-14 | View |
299333 | 28695 | CVE-2007-5338 | URL:http://www.gentoo.org/security/en/glsa/glsa-200711-14.xml | View |
299334 | 28695 | CVE-2007-5338 | HP:HPSBUX02153 | View |
299335 | 28695 | CVE-2007-5338 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 | View |
299336 | 28695 | CVE-2007-5338 | HP:SSRT061181 | View |
299337 | 28695 | CVE-2007-5338 | URL:http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 | View |
299338 | 28695 | CVE-2007-5338 | MANDRIVA:MDKSA-2007:202 | View |
299339 | 28695 | CVE-2007-5338 | URL:http://www.mandriva.com/en/security/advisories?name=MDKSA-2007:202 | View |
299340 | 28695 | CVE-2007-5338 | REDHAT:RHSA-2007:0979 | View |
299341 | 28695 | CVE-2007-5338 | URL:http://www.redhat.com/support/errata/RHSA-2007-0979.html | View |
299342 | 28695 | CVE-2007-5338 | REDHAT:RHSA-2007:0980 | View |
299343 | 28695 | CVE-2007-5338 | URL:http://www.redhat.com/support/errata/RHSA-2007-0980.html | View |
299344 | 28695 | CVE-2007-5338 | REDHAT:RHSA-2007:0981 | View |
299345 | 28695 | CVE-2007-5338 | URL:http://www.redhat.com/support/errata/RHSA-2007-0981.html | View |
299346 | 28695 | CVE-2007-5338 | SUNALERT:201516 | View |
299347 | 28695 | CVE-2007-5338 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1 | View |
299348 | 28695 | CVE-2007-5338 | SUSE:SUSE-SA:2007:057 | View |
299349 | 28695 | CVE-2007-5338 | URL:http://www.novell.com/linux/security/advisories/2007_57_mozilla.html | View |
299350 | 28695 | CVE-2007-5338 | UBUNTU:USN-535-1 | View |
299351 | 28695 | CVE-2007-5338 | URL:http://www.ubuntulinux.org/support/documentation/usn/usn-535-1 | View |
299352 | 28695 | CVE-2007-5338 | UBUNTU:USN-536-1 | View |
299353 | 28695 | CVE-2007-5338 | URL:http://www.ubuntu.com/usn/usn-536-1 | View |
299354 | 28695 | CVE-2007-5338 | BID:26132 | View |
299355 | 28695 | CVE-2007-5338 | URL:http://www.securityfocus.com/bid/26132 | View |
299356 | 28695 | CVE-2007-5338 | OVAL:oval:org.mitre.oval:def:10965 | View |
299357 | 28695 | CVE-2007-5338 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10965 | View |
299358 | 28695 | CVE-2007-5338 | VUPEN:ADV-2007-3544 | View |
299359 | 28695 | CVE-2007-5338 | URL:http://www.vupen.com/english/advisories/2007/3544 | View |
299360 | 28695 | CVE-2007-5338 | VUPEN:ADV-2007-3587 | View |
299361 | 28695 | CVE-2007-5338 | URL:http://www.vupen.com/english/advisories/2007/3587 | View |
299362 | 28695 | CVE-2007-5338 | VUPEN:ADV-2008-0083 | View |
299363 | 28695 | CVE-2007-5338 | URL:http://www.vupen.com/english/advisories/2008/0083 | View |
299364 | 28695 | CVE-2007-5338 | SECTRACK:1018836 | View |
299365 | 28695 | CVE-2007-5338 | URL:http://securitytracker.com/id?1018836 | View |
299366 | 28695 | CVE-2007-5338 | SECUNIA:27276 | View |
299367 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27276 | View |
299368 | 28695 | CVE-2007-5338 | SECUNIA:27325 | View |
299369 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27325 | View |
299370 | 28695 | CVE-2007-5338 | SECUNIA:27327 | View |
299371 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27327 | View |
299372 | 28695 | CVE-2007-5338 | SECUNIA:27335 | View |
299373 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27335 | View |
299374 | 28695 | CVE-2007-5338 | SECUNIA:27356 | View |
299375 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27356 | View |
299376 | 28695 | CVE-2007-5338 | SECUNIA:27383 | View |
299377 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27383 | View |
299378 | 28695 | CVE-2007-5338 | SECUNIA:27425 | View |
299379 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27425 | View |
299380 | 28695 | CVE-2007-5338 | SECUNIA:27403 | View |
299381 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27403 | View |
299382 | 28695 | CVE-2007-5338 | SECUNIA:27480 | View |
299383 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27480 | View |
299384 | 28695 | CVE-2007-5338 | SECUNIA:27387 | View |
299385 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27387 | View |
299386 | 28695 | CVE-2007-5338 | SECUNIA:27298 | View |
299387 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27298 | View |
299388 | 28695 | CVE-2007-5338 | SECUNIA:27311 | View |
299389 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27311 | View |
299390 | 28695 | CVE-2007-5338 | SECUNIA:27315 | View |
299391 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27315 | View |
299392 | 28695 | CVE-2007-5338 | SECUNIA:27336 | View |
299393 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27336 | View |
299394 | 28695 | CVE-2007-5338 | SECUNIA:27665 | View |
299395 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27665 | View |
299396 | 28695 | CVE-2007-5338 | SECUNIA:27414 | View |
299397 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27414 | View |
299398 | 28695 | CVE-2007-5338 | SECUNIA:27680 | View |
299399 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27680 | View |
299400 | 28695 | CVE-2007-5338 | SECUNIA:27360 | View |
299401 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/27360 | View |
299402 | 28695 | CVE-2007-5338 | SECUNIA:28398 | View |
299403 | 28695 | CVE-2007-5338 | URL:http://secunia.com/advisories/28398 | View |
299404 | 28695 | CVE-2007-5338 | XF:mozilla-xpcnativewrapper-code-execution(37288) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
52193 | JVNDB-2007-000883 | Mozilla 製品 の Javascript エンジンにおける複数のサービス運用妨害 (DoS) の脆弱性 | Mozilla 製品の Javascript エンジンには、複数のサービス運用妨害 (DoS) 状態となる脆弱性が存在します。 | CVE-2007-5340 | 28695 | 4.3 | http://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000883.html | View |