Loading...
Loading...
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.
December 28, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-6589
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.