CVE-2007-5337

Advisory lineage Upstream: 0 Downstream: 8
Modified
Published: 21 Oct 2007, 20:00
Last modified:07 Aug 2024, 15:24

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
1.72% LOW
2% probability -0.41%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Oct 2007, 20:00
Published
Vulnerability first disclosed
07 Aug 2024, 15:24
Last Modified
Vulnerability information updated

Description

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.72% Percentile: 83%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • mozillafirefox

    ≤ 2.0.0.7

  • mozillaseamonkey

    ≤ 1.1.4

References (47)