CVE-2007-0008Integer Underflow (Wrap or Wraparound) in Mozilla Firefox

CWE-18912 documents6 sources
Severity
6.8MEDIUMNVD
EPSS
17.4%
top 4.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 26
Latest updateMay 3

Description

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages4 packages

NVDmozilla/network_security_services3.11.2, 3.11.3, 3.11.4+2
NVDmozilla/firefox1.5.0.9+40
NVDmozilla/seamonkey1.0.7+7
NVDmozilla/thunderbird1.5.0.9+30

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g474-6mpq-jjm3: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 32022-05-03
CVEList
CVE-2007-0008: Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 32007-02-26

📋Vendor Advisories

3
Ubuntu
Thunderbird vulnerabilities2007-03-07
Ubuntu
Firefox vulnerabilities2007-03-01
Red Hat
NSS: SSLv2 protocol buffer overflows2007-02-01

💬Community

6
Bugzilla
CVE-2007-0008 CVE-2007-0009 NSS: SSLv2 protocol buffer overflows2010-02-15
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-20072007-03-01
Bugzilla
CVE-2007-0775 Multiple Thunderbird flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-20072007-03-01
Bugzilla
CVE-2007-0775 Multiple Firefox flaws (CVE-2007-0777, CVE-2007-0994, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0002007-02-26
Bugzilla
CVE-2007-0775 Multiple Seamonkey flaws (CVE-2007-0777, CVE-2007-0995, CVE-2007-0996, CVE-2006-6077, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0008, CVE-2007-0009, CVE-2007-02007-02-23
CVE-2007-0008 — Integer Underflow (Wrap or Wraparound) | cvebase