VulnerabilityModified
CVE-2007-2060
Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM.
MEDIUM 6.8EPSS 3.17%
Does this matter?
Lower severity and a low EPSS score (3.17%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-zone scripting vulnerability in the Wizz RSS Reader before 2.1.9 extension to Mozilla Firefox allows remote attackers to execute arbitrary Javascript in the browser chrome via the RSS feed DOM.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.17% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- wizz computers/wizz rss reader
- Source
- cve@mitre.org
References
- http://osvdb.org/34534
- http://secunia.com/advisories/24913
- http://wizzrss.blat.co.za/2009/11/17/so-much-for-nsiscriptableunescapehtmlparsefragment/
- http://www.kb.cert.org/vuls/id/319464Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/MIMG-6ZKP4T
- http://www.securityfocus.com/bid/23523
- http://www.vupen.com/english/advisories/2007/1425
- https://addons.mozilla.org/en-US/firefox/addon/424
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33693
- http://osvdb.org/34534
- http://secunia.com/advisories/24913
- http://wizzrss.blat.co.za/2009/11/17/so-much-for-nsiscriptableunescapehtmlparsefragment/
- http://www.kb.cert.org/vuls/id/319464Patch, US Government Resource
- http://www.kb.cert.org/vuls/id/MIMG-6ZKP4T
- http://www.securityfocus.com/bid/23523
- http://www.vupen.com/english/advisories/2007/1425
- https://addons.mozilla.org/en-US/firefox/addon/424
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33693
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.