>> Mozilla Firefox and SeaMonkey "IMG" Tag Handling Remote Code Execution Vulnerability
Title : Mozilla Firefox and SeaMonkey "IMG" Tag Handling Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-0823 CVE ID : CVE-2007-0994
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-05
Technical Description
A vulnerability has been identified in Mozilla Firefox and SeaMonkey, which could be exploited by attackers to bypass security restrictions and take complete control of an affected system. This issue is due to a regression error when processing certain "IMG" tags, which could be exploited by attackers to bypass restrictions specified in the global preferences and execute arbitrary code by tricking a user into visiting a malicious web page containing a "javascript" URI in the "SRC" attribute of an "IMG" element.