← All CVEs

CVE-2007-1562

medium · 6.8

The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.

6.8
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2007-03-21
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
mozillafirefox>= 1.5, < 1.5.0.11
mozillafirefox>= 2.0, < 2.0.0.3
canonicalubuntu_linux5.10
canonicalubuntu_linux6.06
canonicalubuntu_linux6.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1562