CVE Database
/

CVE-2007-3845

Back to search

CVE-2007-3845

Published: Aug 8, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-503-1
vendor-advisory
x_refsource_UBUNTU
MDVSA-2008:047
vendor-advisory
x_refsource_MANDRIVA
27414
third-party-advisory
x_refsource_SECUNIA
HPSBUX02156
vendor-advisory
x_refsource_HP
26393
third-party-advisory
x_refsource_SECUNIA
26303
third-party-advisory
x_refsource_SECUNIA
ADV-2007-4256
vdb-entry
x_refsource_VUPEN
25053
vdb-entry
x_refsource_BID
26309
third-party-advisory
x_refsource_SECUNIA
HPSBUX02153
vendor-advisory
x_refsource_HP
MDKSA-2007:152
vendor-advisory
x_refsource_MANDRIVA
DSA-1345
vendor-advisory
x_refsource_DEBIAN
DSA-1391
vendor-advisory
x_refsource_DEBIAN
DSA-1346
vendor-advisory
x_refsource_DEBIAN
MDVSA-2007:047
vendor-advisory
x_refsource_MANDRIVA
28135
third-party-advisory
x_refsource_SECUNIA
SSRT061236
vendor-advisory
x_refsource_HP
ADV-2008-0082
vdb-entry
x_refsource_VUPEN
103177
vendor-advisory
x_refsource_SUNALERT
USN-493-1
vendor-advisory
x_refsource_UBUNTU
26234
third-party-advisory
x_refsource_SECUNIA
SSRT061181
vendor-advisory
x_refsource_HP
DSA-1344
vendor-advisory
x_refsource_DEBIAN
26258
third-party-advisory
x_refsource_SECUNIA
27326
third-party-advisory
x_refsource_SECUNIA
26331
third-party-advisory
x_refsource_SECUNIA
20070801 FLEA-2007-0039-1 firefox
mailing-list
x_refsource_BUGTRAQ
201516
vendor-advisory
x_refsource_SUNALERT
20070803 FLEA-2007-0040-1 thunderbird
mailing-list
x_refsource_BUGTRAQ
26335
third-party-advisory
x_refsource_SECUNIA
26572
third-party-advisory
x_refsource_SECUNIA
SSA:2007-213-01
vendor-advisory
x_refsource_SLACKWARE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now