CVE-2007-0009
medium · 6.8Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
6.8
CVSS
50.4%
EPSS (exploit prob.)
99th
EPSS percentile
2007-02-26
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | >= 1.5, < 1.5.0.10 |
| mozilla | firefox | >= 2.0, < 2.0.0.2 |
| mozilla | network_security_services | < 3.11.5 |
| mozilla | seamonkey | < 1.0.8 |
| mozilla | thunderbird | < 1.5.0.10 |
| debian | debian_linux | 3.1 |
| debian | debian_linux | 4.0 |
| canonical | ubuntu_linux | 5.10 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc
- ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc
- http://fedoranews.org/cms/node/2709
- http://fedoranews.org/cms/node/2711
- http://fedoranews.org/cms/node/2747
- http://fedoranews.org/cms/node/2749
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483
- http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html
- http://rhn.redhat.com/errata/RHSA-2007-0077.html
- http://secunia.com/advisories/24253
- http://secunia.com/advisories/24277
- http://secunia.com/advisories/24287
- http://secunia.com/advisories/24290
- http://secunia.com/advisories/24293
- http://secunia.com/advisories/24333
- http://secunia.com/advisories/24342
- http://secunia.com/advisories/24343
- http://secunia.com/advisories/24384
- http://secunia.com/advisories/24389
- http://secunia.com/advisories/24395
- http://secunia.com/advisories/24406
- http://secunia.com/advisories/24410
- http://secunia.com/advisories/24455
- http://secunia.com/advisories/24456
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-0009