VDB
CVE-2007-3845
CVE-2007-3845
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."
EPSS 5.70% · 92.5th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
5.70%
92.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mozilla | thunderbird | 2.0.0.5 |
| mozilla | firefox | 2.0.0.5 |
| n/a | n/a | n/a |
| mozilla | seamonkey | 1.1.3 |
Timeline
- Aug 8, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- http://www.mozilla.org/security/announce/2007/mfsa2007-27.html url
- USN-503-1 vendor-advisory
- 27414 third-party-advisory
- ADV-2007-4256 vdb
- 25053 vdb
- 26309 third-party-advisory
- DSA-1345 vendor-advisory
- 28135 third-party-advisory
- SSRT061236 vendor-advisory
- 26234 third-party-advisory
- SSRT061181 vendor-advisory
- DSA-1344 vendor-advisory
- 27326 third-party-advisory
- 20070801 FLEA-2007-0039-1 firefox mailing-list
- 201516 vendor-advisory
- 20070803 FLEA-2007-0040-1 thunderbird mailing-list
- SSA:2007-213-01 vendor-advisory
- https://issues.rpath.com/browse/RPL-1600 url
- MDVSA-2008:047 vendor-advisory
- 26393 third-party-advisory
…and 15 more