CVE-2007-0008
published 2007-02-26CVE-2007-0008: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.33%
90.1th percentile
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 1.5.0.9 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2007-03-07·CVSS 6.8
CVE-2007-0008 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Thunderbird vulnerabilities
The SSLv2 protocol support in the NSS library did not sufficiently
check the validity of public keys presented with a SSL certificate. A
malicious SSL web site using SSLv2 could potentially exploit this to
execute arbitrary code with the user's privileges. (CVE-2007-0008)
The SSLv2 protocol support in the NSS library did not sufficiently
verify the validity of client master keys presented in an SSL client
certificate. A remote attacker could exploit this to execute arbitrary
code in a server application that uses the NSS library. (CVE-2007-0009)
Various flaws have been reported that could allow an attacker to execute
arbitrary code with user privileges by tricking the user into opening a
malicious web page. (CVE-20
Ubuntu
Firefox regression
vendor_ubuntu·2007-03-02·CVSS 5.0
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: Firefox regression
USN-428-1 fixed vulnerabilities in Firefox 1.5. However, changes to
library paths caused applications depending on libnss3 to fail to start
up. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Several flaws have been found that could be used to perform Cross-site
scripting attacks. A malicious web site could exploit these to modify
the contents or steal confidential data (such as passwords) from other
opened web pages. (CVE-2006-6077, CVE-2007-0780, CVE-2007-0800,
CVE-2007-0981, CVE-2007-0995, CVE-2007-0996)
The SSLv2 protocol support in the NSS library did not sufficiently
check the validity of public keys presented with a SSL certificate. A
malicious SSL web site using SSLv2 could pot
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-03-01·CVSS 5.0
CVE-2007-1092 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Several flaws have been found that could be used to perform Cross-site
scripting attacks. A malicious web site could exploit these to modify
the contents or steal confidential data (such as passwords) from other
opened web pages. (CVE-2006-6077, CVE-2007-0780, CVE-2007-0800,
CVE-2007-0981, CVE-2007-0995, CVE-2007-0996)
The SSLv2 protocol support in the NSS library did not sufficiently
check the validity of public keys presented with a SSL certificate. A
malicious SSL web site using SSLv2 could potentially exploit this to
execute arbitrary code with the user's privileges. (CVE-2007-0008)
The SSLv2 protocol support in the NSS library did not sufficiently
verify the validity of client master keys presented in an SSL client
ce
Red Hat
NSS: SSLv2 protocol buffer overflows
vendor_redhat·2007-02-01·CVSS 6.8
CVE-2007-0008 [MEDIUM] NSS: SSLv2 protocol buffer overflows
NSS: SSLv2 protocol buffer overflows
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.
GHSA
GHSA-g474-6mpq-jjm3: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3
ghsa_unreviewed·2022-05-03
CVE-2007-0008 [MEDIUM] GHSA-g474-6mpq-jjm3: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0008 CVE-2007-0009 NSS: SSLv2 protocol buffer overflows
bugzilla·2010-02-15·CVSS 6.8
CVE-2007-0008 [MEDIUM] CVE-2007-0008 CVE-2007-0009 NSS: SSLv2 protocol buffer overflows
CVE-2007-0008 CVE-2007-0009 NSS: SSLv2 protocol buffer overflows
Two security flaws were reported in NSS's SSLv2 protocol implementation:
CVE-2007-0008:
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.
https://bugzilla.mozilla.org/show_bug.cgi?id=364319
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482
CVE-2007-0009:
Stack-based buffer overflow in the
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
bugzilla·2007-03-01·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981, CVE-2007-1282)
+++ This bug was initially created as a clone of Bug #230542 +++
The Mozilla project is releasing Thunderbird 1.5.0.10 to fix several flaws:
mfsa2007-01
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla pa
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
bugzilla·2007-03-01·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981, CVE-2007-1092)
+++ This bug was initially created as a clone of Bug #229802 +++
The Mozilla project is releasing Thunderbird 1.5.0.10 to fix several flaws:
mfsa2007-01
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla pa
Bugzilla
CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0994, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-000
bugzilla·2007-02-26·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0994, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-000
CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0994, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981)
+++ This bug was initially created as a clone of Bug #229802 +++
The Mozilla project is releasing Firefox 1.5.0.10 to fix several flaws:
mfsa2007-01
impact=critical,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla parser for
Bugzilla
CVE-2007-0775 Multiple Seamonkey flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0
bugzilla·2007-02-23·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Seamonkey flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0
CVE-2007-0775 Multiple Seamonkey flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981)
+++ This bug was initially created as a clone of Bug #229802 +++
The Mozilla project is releasing Seamonkey 1.0.8 to fix several flaws:
mfsa2007-01
impact=critical,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla parser formerly ignored
Bugzilla
CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-098
bugzilla·2007-02-23·CVSS 5.0
CVE-2007-0775 [MEDIUM] CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-098
CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-0981)
The Mozilla project is releasing Firefox 1.5.0.10 to fix several flaws:
mfsa2007-01
impact=critical,source=mozilla,reported=20070222,public=20070223
CVE-2007-0775
Jesse Ruderman, Martijn Wargers and Olli Pettay reported crashes in the
layout engine
CVE-2007-0777
Brian Crowder, Igor Bukanov, Johnny Stenback, moz_bug_r_a4 and shutdown
reported potential memory corruption in the JavaScript engine
mfsa2007-02
impact=moderate,source=mozilla,reported=20070222,public=20070223
CVE-2007-0995
The Mozilla parser formerly ignored invalid trailing characters in HTML tag
attribute names. This could
ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.ascftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://fedoranews.org/cms/node/2709http://fedoranews.org/cms/node/2711http://fedoranews.org/cms/node/2713http://fedoranews.org/cms/node/2728http://fedoranews.org/cms/node/2747http://fedoranews.org/cms/node/2749http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.htmlhttp://rhn.redhat.com/errata/RHSA-2007-0077.htmlhttp://secunia.com/advisories/24205http://secunia.com/advisories/24238http://secunia.com/advisories/24252http://secunia.com/advisories/24253http://secunia.com/advisories/24277http://secunia.com/advisories/24287http://secunia.com/advisories/24290http://secunia.com/advisories/24293http://secunia.com/advisories/24320http://secunia.com/advisories/24328http://secunia.com/advisories/24333http://secunia.com/advisories/24342http://secunia.com/advisories/24343http://secunia.com/advisories/24384http://secunia.com/advisories/24389http://secunia.com/advisories/24395http://secunia.com/advisories/24406http://secunia.com/advisories/24410http://secunia.com/advisories/24455http://secunia.com/advisories/24456http://secunia.com/advisories/24457http://secunia.com/advisories/24522http://secunia.com/advisories/24562http://secunia.com/advisories/24650http://secunia.com/advisories/24703http://secunia.com/advisories/25588http://secunia.com/advisories/25597http://security.gentoo.org/glsa/glsa-200703-18.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1http://www.debian.org/security/2007/dsa-1336http://www.gentoo.org/security/en/glsa/glsa-200703-22.xmlhttp://www.kb.cert.org/vuls/id/377812http://www.mandriva.com/security/advisories?name=MDKSA-2007:050http://www.mandriva.com/security/advisories?name=MDKSA-2007:052http://www.mozilla.org/security/announce/2007/mfsa2007-06.htmlhttp://www.novell.com/linux/security/advisories/2007_22_mozilla.htmlhttp://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlhttp://www.osvdb.org/32105http://www.redhat.com/support/errata/RHSA-2007-0078.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0079.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0097.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0108.htmlhttp://www.securityfocus.com/archive/1/461336/100/0/threadedhttp://www.securityfocus.com/archive/1/461809/100/0/threadedhttp://www.securityfocus.com/bid/22694http://www.securityfocus.com/bid/64758http://www.securitytracker.com/id?1017696http://www.ubuntu.com/usn/usn-428-1http://www.ubuntu.com/usn/usn-431-1http://www.vupen.com/english/advisories/2007/0718http://www.vupen.com/english/advisories/2007/0719http://www.vupen.com/english/advisories/2007/1165http://www.vupen.com/english/advisories/2007/2141https://bugzilla.mozilla.org/show_bug.cgi?id=364319https://exchange.xforce.ibmcloud.com/vulnerabilities/32666https://issues.rpath.com/browse/RPL-1081https://issues.rpath.com/browse/RPL-1103https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10502ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.ascftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://fedoranews.org/cms/node/2709http://fedoranews.org/cms/node/2711http://fedoranews.org/cms/node/2713http://fedoranews.org/cms/node/2728http://fedoranews.org/cms/node/2747http://fedoranews.org/cms/node/2749http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=482http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.htmlhttp://rhn.redhat.com/errata/RHSA-2007-0077.htmlhttp://secunia.com/advisories/24205http://secunia.com/advisories/24238http://secunia.com/advisories/24252http://secunia.com/advisories/24253http://secunia.com/advisories/24277http://secunia.com/advisories/24287http://secunia.com/advisories/24290http://secunia.com/advisories/24293http://secunia.com/advisories/24320http://secunia.com/advisories/24328http://secunia.com/advisories/24333http://secunia.com/advisories/24342http://secunia.com/advisories/24343http://secunia.com/advisories/24384
+ 48 more references
2007-02-26
Published