Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-0009 | First vendor Publication | 2007-02-26 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.8 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0009 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:10174 | |||
Oval ID: | oval:org.mitre.oval:def:10174 | ||
Title: | Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values. | ||
Description: | Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2007-0009 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2009-10-10 | Name : SLES9: Security update for Mozilla suite File : nvt/sles9p5012115.nasl |
2009-04-09 | Name : Mandriva Update for mozilla-thunderbird MDKSA-2007:052 (mozilla-thunderbird) File : nvt/gb_mandriva_MDKSA_2007_052.nasl |
2009-04-09 | Name : Mandriva Update for mozilla-firefox MDKSA-2007:050-1 (mozilla-firefox) File : nvt/gb_mandriva_MDKSA_2007_050_1.nasl |
2009-04-09 | Name : Mandriva Update for mozilla-firefox MDKSA-2007:050 (mozilla-firefox) File : nvt/gb_mandriva_MDKSA_2007_050.nasl |
2009-03-23 | Name : Ubuntu Update for firefox vulnerabilities USN-428-1 File : nvt/gb_ubuntu_USN_428_1.nasl |
2009-03-23 | Name : Ubuntu Update for firefox regression USN-428-2 File : nvt/gb_ubuntu_USN_428_2.nasl |
2009-03-23 | Name : Ubuntu Update for mozilla-thunderbird vulnerabilities USN-431-1 File : nvt/gb_ubuntu_USN_431_1.nasl |
2009-02-27 | Name : Fedora Update for nspr FEDORA-2007-279 File : nvt/gb_fedora_2007_279_nspr_fc6.nasl |
2009-02-27 | Name : Fedora Update for nss FEDORA-2007-279 File : nvt/gb_fedora_2007_279_nss_fc6.nasl |
2009-02-27 | Name : Fedora Update for nss FEDORA-2007-278 File : nvt/gb_fedora_2007_278_nss_fc5.nasl |
2009-02-27 | Name : Fedora Update for nspr FEDORA-2007-278 File : nvt/gb_fedora_2007_278_nspr_fc5.nasl |
2009-01-28 | Name : SuSE Update for MozillaFirefox,seamonkey SUSE-SA:2007:019 File : nvt/gb_suse_2007_019.nasl |
2009-01-28 | Name : SuSE Update for mozilla,MozillaThunderbird,seamonkey SUSE-SA:2007:022 File : nvt/gb_suse_2007_022.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200703-18 (mozilla-thunderbird) File : nvt/glsa_200703_18.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200703-22 (nss) File : nvt/glsa_200703_22.nasl |
2008-09-04 | Name : FreeBSD Ports: firefox File : nvt/freebsd_firefox26.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1336-1 (mozilla-firefox) File : nvt/deb_1336_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
32106 | Mozilla Network Security Services SSLv2 Server Remote Overflow A remote overflow exists in Mozilla Foundation's Network Security Services (NSS) libraries. The vulnerability is due to inadequate error checking in the Network Security Services (NSS) code that is responsible for handling the Client Master Key. A remote attacker can exploit the vulnerability with a specially-crafted SSLv2 certificate containing a Client Master Key with invalid length values. This may result in a stack-based buffer overflow allowing the attacker to crash the affected server or to execute arbitrary code in the context of the affected server, resulting in a loss of availability and/or integrity. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2014-01-16 | IAVM : 2014-A-0009 - Multiple Vulnerabilities in Oracle Fusion Middleware Severity : Category I - VMSKEY : V0043395 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Mozilla Network Security Services SSLv2 stack overflow attempt RuleID : 11672 - Revision : 8 - Type : BROWSER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2007-0079.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing a security update. File : oraclelinux_ELSA-2007-0078.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0077.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2007-0077-2.nasl - Type : ACT_GATHER_INFO |
2013-01-24 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2007-0108.nasl - Type : ACT_GATHER_INFO |
2007-12-13 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_MozillaFirefox-2683.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-431-1.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-428-2.nasl - Type : ACT_GATHER_INFO |
2007-11-10 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-428-1.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_seamonkey-2811.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_seamonkey-2691.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_MozillaFirefox-2699.nasl - Type : ACT_GATHER_INFO |
2007-10-17 | Name : The remote openSUSE host is missing a security update. File : suse_MozillaFirefox-2647.nasl - Type : ACT_GATHER_INFO |
2007-07-27 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1336.nasl - Type : ACT_GATHER_INFO |
2007-05-25 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0097.nasl - Type : ACT_GATHER_INFO |
2007-04-06 | Name : The remote Windows host uses a library that may allow remote code execution. File : sun_java_es_nss_code_exec.nasl - Type : ACT_GATHER_INFO |
2007-03-26 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200703-22.nasl - Type : ACT_GATHER_INFO |
2007-03-19 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200703-18.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-066-03.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-066-04.nasl - Type : ACT_GATHER_INFO |
2007-03-12 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2007-066-05.nasl - Type : ACT_GATHER_INFO |
2007-03-07 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-052.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2007-0078.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2007-0078.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-308.nasl - Type : ACT_GATHER_INFO |
2007-03-06 | Name : The remote Fedora Core host is missing a security update. File : fedora_2007-309.nasl - Type : ACT_GATHER_INFO |
2007-03-02 | Name : The remote Windows host contains a mail client that is affected by multiple v... File : mozilla_thunderbird_15010.nasl - Type : ACT_GATHER_INFO |
2007-03-02 | Name : The remote Mandrake Linux host is missing one or more security updates. File : mandrake_MDKSA-2007-050.nasl - Type : ACT_GATHER_INFO |
2007-02-28 | Name : A web browser on the remote host is prone to multiple flaws. File : seamonkey_108.nasl - Type : ACT_GATHER_INFO |
2007-02-27 | Name : The remote Fedora Core host is missing one or more security updates. File : fedora_2007-278.nasl - Type : ACT_GATHER_INFO |
2007-02-27 | Name : The remote Fedora Core host is missing one or more security updates. File : fedora_2007-279.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote Red Hat host is missing a security update. File : redhat-RHSA-2007-0079.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2007-0077.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote CentOS host is missing a security update. File : centos_RHSA-2007-0079.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2007-0077.nasl - Type : ACT_GATHER_INFO |
2007-02-26 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_12bd6ecfc43011db95c5000c6ec775d9.nasl - Type : ACT_GATHER_INFO |
2007-02-24 | Name : The remote Windows host contains a web browser that is affected by multiple v... File : mozilla_firefox_15010.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2025-02-07 01:06:27 |
|
2024-11-28 23:18:06 |
|
2024-11-28 12:11:10 |
|
2024-11-01 01:06:07 |
|
2024-10-22 12:06:10 |
|
2024-08-02 12:06:06 |
|
2024-08-02 01:02:09 |
|
2024-02-10 01:05:31 |
|
2024-02-02 01:05:45 |
|
2024-02-01 12:02:09 |
|
2023-09-05 12:05:22 |
|
2023-09-05 01:02:00 |
|
2023-09-02 12:05:27 |
|
2023-09-02 01:02:00 |
|
2023-08-12 12:06:23 |
|
2023-08-12 01:02:00 |
|
2023-08-11 12:05:30 |
|
2023-08-11 01:02:04 |
|
2023-08-06 12:05:14 |
|
2023-08-06 01:02:01 |
|
2023-08-04 12:05:20 |
|
2023-08-04 01:02:04 |
|
2023-07-14 12:05:18 |
|
2023-07-14 01:02:02 |
|
2023-03-29 01:05:53 |
|
2023-03-28 12:02:07 |
|
2022-10-11 12:04:41 |
|
2022-10-11 01:01:52 |
|
2021-05-04 12:05:53 |
|
2021-04-22 01:06:25 |
|
2020-10-14 01:02:32 |
|
2020-10-03 01:02:30 |
|
2020-05-29 01:02:20 |
|
2020-05-23 01:37:38 |
|
2020-05-23 00:19:03 |
|
2019-10-10 05:19:25 |
|
2019-06-25 12:01:41 |
|
2019-01-30 12:02:06 |
|
2018-11-30 12:01:57 |
|
2018-10-20 00:19:35 |
|
2018-10-17 21:19:32 |
|
2018-10-16 21:19:45 |
|
2018-08-10 12:01:22 |
|
2018-07-13 01:02:17 |
|
2018-01-11 01:01:20 |
|
2017-11-22 12:02:12 |
|
2017-11-21 12:01:45 |
|
2017-10-11 09:23:49 |
|
2017-07-29 12:01:55 |
|
2016-06-28 16:02:59 |
|
2016-04-26 15:35:12 |
|
2014-02-17 10:38:26 |
|
2014-01-19 21:23:44 |
|
2014-01-18 00:18:31 |
|
2014-01-17 13:18:57 |
|
2013-05-11 00:39:24 |
|