{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2007-02-07T11:28:00Z",
  "id": "CVE-2007-0801",
  "details": "The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/24393"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/24437"
    },
    {
      "type": "ADVISORY",
      "url": "http://security.gentoo.org/glsa/glsa-200703-04.xml"
    },
    {
      "type": "ADVISORY",
      "url": "http://www.securityfocus.com/bid/22396"
    },
    {
      "type": "EVIDENCE",
      "url": "http://www.securityfocus.com/bid/22396"
    },
    {
      "type": "WEB",
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200703-08.xml"
    },
    {
      "type": "WEB",
      "url": "http://www.osvdb.org/32108"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/archive/1/459162/100/0/threaded"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/archive/1/459163/100/0/threaded"
    }
  ]
}
