CVE-2007-4038
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via…
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking Thunderbird.exe, a similar issue to CVE-2007-3670.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- mozilla/firefox · mozilla/thunderbird
- Source
- cve@mitre.org
References
- http://larholm.com/2007/07/25/mozilla-protocol-abuse/
- http://seclists.org/fulldisclosure/2007/Jul/0557.html
- http://www.securityfocus.com/archive/1/474624/100/0/threaded
- http://www.securityfocus.com/archive/1/474686/100/0/threaded
- http://larholm.com/2007/07/25/mozilla-protocol-abuse/
- http://seclists.org/fulldisclosure/2007/Jul/0557.html
- http://www.securityfocus.com/archive/1/474624/100/0/threaded
- http://www.securityfocus.com/archive/1/474686/100/0/threaded
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.