Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2007-3670 First vendor Publication 2007-07-10
Vendor Cve Last vendor Modification 2021-07-23

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3670

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 6
Application 1

OpenVAS Exploits

Date Description
2009-10-10 Name : SLES9: Security update for Mozilla
File : nvt/sles9p5011293.nasl
2009-05-05 Name : HP-UX Update for Thunderbird HPSBUX02156
File : nvt/gb_hp_ux_HPSBUX02156.nasl
2009-04-09 Name : Mandriva Update for mozilla-firefox MDKSA-2007:152 (mozilla-firefox)
File : nvt/gb_mandriva_MDKSA_2007_152.nasl
2009-03-23 Name : Ubuntu Update for mozilla-thunderbird vulnerabilities USN-503-1
File : nvt/gb_ubuntu_USN_503_1.nasl
2009-01-28 Name : SuSE Update for MozillaFirefox,MozillaThunderbird,Seamonkey SUSE-SA:2007:049
File : nvt/gb_suse_2007_049.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
38017 Microsoft IE with Mozilla Firefox Cross-browser Command Execution

Nessus® Vulnerability Scanner

Date Description
2009-02-16 Name : The remote host contains a web browser that is prone to a cross- browser scri...
File : google_chrome_1_0_154_48.nasl - Type : ACT_GATHER_INFO
2007-12-13 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_MozillaFirefox-3932.nasl - Type : ACT_GATHER_INFO
2007-11-10 Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-503-1.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaFirefox-3933.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaFirefox-3935.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_MozillaThunderbird-3973.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_seamonkey-3984.nasl - Type : ACT_GATHER_INFO
2007-10-17 Name : The remote openSUSE host is missing a security update.
File : suse_seamonkey-3986.nasl - Type : ACT_GATHER_INFO
2007-08-02 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2007-152.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/24837
BUGTRAQ http://www.securityfocus.com/archive/1/473276/100/0/threaded
CERT http://www.us-cert.gov/cas/techalerts/TA07-199A.html
CERT-VN http://www.kb.cert.org/vuls/id/358017
CONFIRM ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt
http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html
http://www.mozilla.org/security/announce/2007/mfsa2007-23.html
http://www.mozilla.org/security/announce/2007/mfsa2007-40.html
FULLDISC http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html
HP http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579
IDEFENSE http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=565
MANDRIVA http://www.mandriva.com/security/advisories?name=MDKSA-2007:152
MISC http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-ha...
http://larholm.com/2007/07/10/internet-explorer-0day-exploit/
http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefo...
http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/
http://www.virusbtn.com/news/virus_news/2007/07_11.xml
http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html
OSVDB http://osvdb.org/38017
SECTRACK http://www.securitytracker.com/id?1018351
http://www.securitytracker.com/id?1018360
SECUNIA http://secunia.com/advisories/25984
http://secunia.com/advisories/26096
http://secunia.com/advisories/26149
http://secunia.com/advisories/26204
http://secunia.com/advisories/26216
http://secunia.com/advisories/26258
http://secunia.com/advisories/26271
http://secunia.com/advisories/26572
http://secunia.com/advisories/28179
http://secunia.com/advisories/28363
SUSE http://www.novell.com/linux/security/advisories/2007_49_mozilla.html
UBUNTU http://www.ubuntu.com/usn/usn-503-1
VUPEN http://www.vupen.com/english/advisories/2007/2473
http://www.vupen.com/english/advisories/2007/2565
http://www.vupen.com/english/advisories/2007/4272
http://www.vupen.com/english/advisories/2008/0082
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/35346

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
Date Informations
2021-07-27 00:24:34
  • Multiple Updates
2021-07-24 01:44:12
  • Multiple Updates
2021-07-24 01:03:58
  • Multiple Updates
2021-07-23 21:25:01
  • Multiple Updates
2021-07-23 17:24:38
  • Multiple Updates
2021-05-04 12:06:05
  • Multiple Updates
2021-04-22 01:06:37
  • Multiple Updates
2020-05-23 00:20:05
  • Multiple Updates
2018-10-16 00:19:09
  • Multiple Updates
2017-07-29 12:02:22
  • Multiple Updates
2016-06-28 16:43:34
  • Multiple Updates
2016-04-26 16:21:08
  • Multiple Updates
2014-02-17 10:40:48
  • Multiple Updates
2013-08-22 13:18:52
  • Multiple Updates
2013-05-11 10:31:00
  • Multiple Updates