CVE-2007-3736

Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 18 Jul 2007, 17:00
Last modified:07 Aug 2024, 14:28

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
2.05% LOW
2% probability -0.56%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Jul 2007, 17:00
Published
Vulnerability first disclosed
07 Aug 2024, 14:28
Last Modified
Vulnerability information updated

Description

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 2.05% Percentile: 84%

Affected Systems

  • UnknownFirefox

    2.0 | 2.0.0.1 | 2.0.0.2 | 2.0.0.3 | 2.0.0.4

References (43)