CVE-2007-4041

Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 27 Jul 2007, 22:00
Last modified:07 Aug 2024, 14:37

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
10.87% MEDIUM
11% probability +0.17%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Jul 2007, 22:00
Published
Vulnerability first disclosed
07 Aug 2024, 14:37
Last Modified
Vulnerability information updated

Description

Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 10.87% Percentile: 94%

Techniques & Countermeasures

  • CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Affected Systems

  • UnknownInternet Explorer

    7

  • mozillafirefox

    2.0.0.5 | 3.0:alpha

References (6)