cbcvebase.
CVE-2007-0009
published 2007-02-26

CVE-2007-0009: Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before…

PriorityP353medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
50.36%
98.8th percentile
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
mozillafirefox>= 1.5 < 1.5.0.101.5.0.10
mozillafirefox>= 2.0 < 2.0.0.22.0.0.2
mozillanetwork_security_services< 3.11.53.11.5
mozillaseamonkey< 1.0.81.0.8
mozillathunderbird< 1.5.0.101.5.0.10

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector targets SSLv2 Client Master Key message with invalid length values, triggering a stack-based buffer overflow in NSS; monitor for malformed SSLv2 ClientMasterKey handshake messages
  • The vulnerability is exploitable in server applications using the NSS library that accept SSLv2 client certificates; focus detection on SSLv2 handshake traffic where client master key length fields are anomalous
  • Reference iDefense advisory ID 483 documents the specific exploit details for CVE-2007-0009; correlate with iDefense advisory ID 482 for the related CVE-2007-0008 SSLv2 heap overflow
  • ·Vulnerable NSS versions are strictly before 3.11.5; affected products include Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and Sun Java System server products before 20070611
  • ·The attack surface only exists when SSLv2 protocol support is enabled in the NSS library; disabling SSLv2 eliminates the attack vector entirely

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.