Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-0008 | First vendor Publication | 2007-02-26 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0008 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10502 | |||
Oval ID: | oval:org.mitre.oval:def:10502 | ||
Title: | Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow. | ||
Description: | Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2007-0008 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-10-10 | Name : SLES9: Security update for Mozilla suite File : nvt/sles9p5012115.nasl |
2009-04-09 | Name : Mandriva Update for mozilla-thunderbird MDKSA-2007:052 (mozilla-thunderbird) File : nvt/gb_mandriva_MDKSA_2007_052.nasl |
2009-04-09 | Name : Mandriva Update for mozilla-firefox MDKSA-2007:050-1 (mozilla-firefox) File : nvt/gb_mandriva_MDKSA_2007_050_1.nasl |
2009-04-09 | Name : Mandriva Update for mozilla-firefox MDKSA-2007:050 (mozilla-firefox) File : nvt/gb_mandriva_MDKSA_2007_050.nasl |
2009-03-23 | Name : Ubuntu Update for firefox vulnerabilities USN-428-1 File : nvt/gb_ubuntu_USN_428_1.nasl |
2009-03-23 | Name : Ubuntu Update for firefox regression USN-428-2 File : nvt/gb_ubuntu_USN_428_2.nasl |
2009-03-23 | Name : Ubuntu Update for mozilla-thunderbird vulnerabilities USN-431-1 File : nvt/gb_ubuntu_USN_431_1.nasl |
2009-02-27 | Name : Fedora Update for nspr FEDORA-2007-279 File : nvt/gb_fedora_2007_279_nspr_fc6.nasl |
2009-02-27 | Name : Fedora Update for nss FEDORA-2007-279 File : nvt/gb_fedora_2007_279_nss_fc6.nasl |
2009-02-27 | Name : Fedora Update for nss FEDORA-2007-278 File : nvt/gb_fedora_2007_278_nss_fc5.nasl |
2009-02-27 | Name : Fedora Update for nspr FEDORA-2007-278 File : nvt/gb_fedora_2007_278_nspr_fc5.nasl |
2009-01-28 | Name : SuSE Update for MozillaFirefox,seamonkey SUSE-SA:2007:019 File : nvt/gb_suse_2007_019.nasl |
2009-01-28 | Name : SuSE Update for mozilla,MozillaThunderbird,seamonkey SUSE-SA:2007:022 File : nvt/gb_suse_2007_022.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200703-18 (mozilla-thunderbird) File : nvt/glsa_200703_18.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200703-22 (nss) File : nvt/glsa_200703_22.nasl |
2008-09-04 | Name : FreeBSD Ports: firefox File : nvt/freebsd_firefox26.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1336-1 (mozilla-firefox) File : nvt/deb_1336_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
32105 | Mozilla Multiple Products NSS SSLv2 Client Overflow A remote overflow exists in multiple versions of Mozilla Firefox, Mozilla Network Security Services (NSS), Mozilla SeaMonkey, and Mozilla Thunderbird. The vulnerability is due to an error in the Network Security Services (NSS) code that can occur when processing certain SSLv2 server messages. The products fail to properly process SSL server certificates which possess an RSA public key that is too small to encrypt the entire SSLv2 "Master Secret". This may result in a heap-based overflow and may allow an attacker execution of arbitrary code, resulting in a loss of integrity and/or availability. |
Snort® IPS/IDS
Date | Description |
---|---|
2018-02-27 | Mozilla Network Security Services heap underflow exploit attempt RuleID : 45539 - Revision : 1 - Type : SERVER-OTHER |
2018-02-27 | Mozilla Network Security Services heap underflow exploit attempt RuleID : 45538 - Revision : 1 - Type : SERVER-OTHER |
2018-02-27 | Mozilla Network Security Services heap underflow exploit attempt RuleID : 45537 - Revision : 1 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2007-0079.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2007-0078.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0077.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0077-2.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2007-0108.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_MozillaFirefox-2683.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-431-1.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-428-2.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-428-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_seamonkey-2811.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_seamonkey-2691.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_MozillaThunderbird-2734.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_MozillaFirefox-2699.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_MozillaFirefox-2647.nasl - Type : ACT_GATHER_INFO |
2007-07-27 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1336.nasl - Type : ACT_GATHER_INFO |
2007-05-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0097.nasl - Type : ACT_GATHER_INFO |
2007-04-06 | Name : The remote Windows host uses a library that may allow remote code execution. File : sun_java_es_nss_code_exec.nasl - Type : ACT_GATHER_INFO |
2007-03-26 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200703-22.nasl - Type : ACT_GATHER_INFO |
2007-03-19 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200703-18.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-066-03.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-066-04.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-066-05.nasl - Type : ACT_GATHER_INFO |
2007-03-07 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-052.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2007-0078.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2007-0078.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-309.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-308.nasl - Type : ACT_GATHER_INFO |
2007-03-02 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-050.nasl - Type : ACT_GATHER_INFO |
2007-02-28 | Name : A web browser on the remote host is prone to multiple flaws. File : seamonkey_108.nasl - Type : ACT_GATHER_INFO |
2007-02-28 | Name : The remote Fedora Core host is missing one or more security updates. File : fedora_2007-293.nasl - Type : ACT_GATHER_INFO |
2007-02-27 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-281.nasl - Type : ACT_GATHER_INFO |
2007-02-27 | Name : The remote Fedora Core host is missing one or more security updates. File : fedora_2007-278.nasl - Type : ACT_GATHER_INFO |
2007-02-27 | Name : The remote Fedora Core host is missing one or more security updates. File : fedora_2007-279.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2007-0079.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0077.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2007-0079.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2007-0077.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_12bd6ecfc43011db95c5000c6ec775d9.nasl - Type : ACT_GATHER_INFO |
2007-02-24 | Name : The remote Windows host contains a web browser that is affected by multiple v... File : mozilla_firefox_15010.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-02-07 01:06:27 |
|
2024-11-28 23:18:06 |
|
2024-11-28 12:11:10 |
|
2024-11-01 01:06:06 |
|
2024-10-22 12:06:10 |
|
2024-08-02 12:06:06 |
|
2024-08-02 01:02:09 |
|
2024-02-10 01:05:31 |
|
2024-02-02 01:05:44 |
|
2024-02-01 12:02:08 |
|
2023-09-05 12:05:22 |
|
2023-09-05 01:01:59 |
|
2023-09-02 12:05:27 |
|
2023-09-02 01:02:00 |
|
2023-08-12 12:06:23 |
|
2023-08-12 01:02:00 |
|
2023-08-11 12:05:30 |
|
2023-08-11 01:02:03 |
|
2023-08-06 12:05:14 |
|
2023-08-06 01:02:01 |
|
2023-08-04 12:05:20 |
|
2023-08-04 01:02:04 |
|
2023-07-14 12:05:18 |
|
2023-07-14 01:02:02 |
|
2023-03-29 01:05:53 |
|
2023-03-28 12:02:07 |
|
2022-10-11 12:04:41 |
|
2022-10-11 01:01:52 |
|
2021-05-04 12:05:10 |
|
2021-04-22 01:05:43 |
|
2020-10-14 01:02:32 |
|
2020-10-03 01:02:30 |
|
2020-05-29 01:02:20 |
|
2020-05-23 01:37:38 |
|
2020-05-23 00:19:02 |
|
2019-06-25 12:01:41 |
|
2019-01-30 12:02:06 |
|
2018-10-16 21:19:45 |
|
2018-07-13 01:02:17 |
|
2017-11-21 12:01:45 |
|
2017-10-11 09:23:49 |
|
2017-07-29 12:01:55 |
|
2016-06-28 16:02:59 |
|
2016-04-26 15:35:11 |
|
2014-05-05 13:22:58 |
|
2014-02-17 10:38:26 |
|
2014-01-17 13:18:56 |
|
2013-05-11 00:39:15 |
|