---
title: "CVE-2007-0996\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2007-0996?format=md
keywords: index, follow
---

# CVE-2007-0996

Publication date 27 February 2007

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2,
and SeaMonkey before 1.0.8 inherit the default charset from the parent
window, which allows remote attackers to conduct cross-site scripting (XSS)
attacks, as demonstrated using the UTF-7 character set.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 7.04 feisty | Fixed 2.0.0.6+1-0ubuntu1 |
| 6.10 edgy | Fixed 2.0.0.6+0dfsg-0ubuntu0.6.10 |
| 6.06 LTS dapper | Fixed 1.5.dfsg+1.5.0.13~prepatch070731-0ubuntu1 |
| lightning-sunbird | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |
| midbrowser | 7.04 feisty | Not in release |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0996)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2007-0996)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2007-0996)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2007-0996)

### Related Ubuntu Security Notices (USN)

+ [USN-428-1](https://usn.ubuntu.com/USN-428-1)
+ Firefox vulnerabilities
+ 1 March 2007

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2007-0996>
