SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3954

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell…

MEDIUM 4.3EPSS 6.67%

Does this matter?

Lower severity and a low EPSS score (6.67%). Track it; it rarely justifies an emergency change on its own.

Description

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking SeaMonkey.exe, a related issue to CVE-2007-3670.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
6.67% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
microsoft/internet explorer · mozilla/seamonkey
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.