CVE-2007-3285
published 2007-06-20CVE-2007-3285: Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2)…
PriorityP424medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.75%
75.6th percentile
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.4 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-07-20·CVSS 4.3
CVE-2007-3089 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-3734,
CVE-2007-3735)
Flaws were discovered in the JavaScript methods addEventListener and
setTimeout which could be used to inject script into another site in
violation of the browser's same-origin policy. A malicious web site
could exploit this to modify the contents, or steal confidential data
(such as passwords), of other web pages. (CVE-2007-3736)
Ronen Zilberman and Michal Zalewski discovered timing attacks in the
JavaScript engine's use of about:blank frames. A malicious web site
could exploit this to modify the content
GHSA
GHSA-fcrm-w52m-c99v: Mozilla Firefox before 2
ghsa_unreviewed·2022-05-03
CVE-2007-3285 [MEDIUM] GHSA-fcrm-w52m-c99v: Mozilla Firefox before 2
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txthttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://osvdb.org/38032http://secunia.com/advisories/26072http://secunia.com/advisories/26149http://secunia.com/advisories/26204http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/28135http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.0x000000.com/?i=333http://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-22.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.securityfocus.com/bid/24447http://www.securitytracker.com/id?1018413http://www.ubuntu.com/usn/usn-490-1http://www.vupen.com/english/advisories/2007/4256https://bugzilla.mozilla.org/show_bug.cgi?id=383478ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txthttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://osvdb.org/38032http://secunia.com/advisories/26072http://secunia.com/advisories/26149http://secunia.com/advisories/26204http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/28135http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.0x000000.com/?i=333http://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-22.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.securityfocus.com/bid/24447http://www.securitytracker.com/id?1018413http://www.ubuntu.com/usn/usn-490-1http://www.vupen.com/english/advisories/2007/4256https://bugzilla.mozilla.org/show_bug.cgi?id=383478
2007-06-20
Published