CVE-2007-3738
published 2007-07-18CVE-2007-3738: Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.80%
88.8th percentile
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openssl: SSL_get_shared_ciphers() off-by-one
vendor_redhat·2007-09-27·CVSS 10.0
CVE-2007-5135 [CRITICAL] CWE-193 openssl: SSL_get_shared_ciphers() off-by-one
openssl: SSL_get_shared_ciphers() off-by-one
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2007-07-20·CVSS 4.3
CVE-2007-3089 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Various flaws were discovered in the layout and JavaScript engines. By
tricking a user into opening a malicious web page, an attacker could
execute arbitrary code with the user's privileges. (CVE-2007-3734,
CVE-2007-3735)
Flaws were discovered in the JavaScript methods addEventListener and
setTimeout which could be used to inject script into another site in
violation of the browser's same-origin policy. A malicious web site
could exploit this to modify the contents, or steal confidential data
(such as passwords), of other web pages. (CVE-2007-3736)
Ronen Zilberman and Michal Zalewski discovered timing attacks in the
JavaScript engine's use of about:blank frames. A malicious web site
could exploit this to modify the content
Red Hat
security flaw
vendor_redhat·2007-07-18·CVSS 9.3
CVE-2007-3738 [CRITICAL] security flaw
security flaw
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
GHSA
GHSA-p4qw-x342-xjwx: Multiple unspecified vulnerabilities in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-03
CVE-2007-3738 [HIGH] GHSA-p4qw-x342-xjwx: Multiple unspecified vulnerabilities in Mozilla Firefox before 2
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-3738 security flaw
bugzilla·2018-08-16·CVSS 9.3
CVE-2007-3738 [CRITICAL] CVE-2007-3738 security flaw
CVE-2007-3738 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
Bugzilla
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
bugzilla·2007-07-17·CVSS 4.3
CVE-2007-3089 [MEDIUM] CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)
Various flaws have been fixed in Firefox 2.0.0.5 Please see the upstream
advisories:
http://www.mozilla.org/projects/security/known-vulnerabilities.html
We are affected by:
MFSA 2007-18
MFSA 2007-19
MFSA 2007-20
MFSA 2007-21
MFSA 2007-24
MFSA 2007-25
Discussion:
It should be noted that CVE-2007-3656 does not affect Thunderbird.
---
epiphany-2.18.3-2.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
firefox-2.0.0.5-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
devhelp-0.13-9.fc7 has been
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txtftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/25589http://secunia.com/advisories/26072http://secunia.com/advisories/26095http://secunia.com/advisories/26103http://secunia.com/advisories/26106http://secunia.com/advisories/26107http://secunia.com/advisories/26149http://secunia.com/advisories/26151http://secunia.com/advisories/26159http://secunia.com/advisories/26179http://secunia.com/advisories/26204http://secunia.com/advisories/26205http://secunia.com/advisories/26211http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/26460http://secunia.com/advisories/28135http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.debian.org/security/2007/dsa-1337http://www.debian.org/security/2007/dsa-1338http://www.debian.org/security/2007/dsa-1339http://www.gentoo.org/security/en/glsa/glsa-200708-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-25.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0722.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0724.htmlhttp://www.securityfocus.com/archive/1/474226/100/0/threadedhttp://www.securityfocus.com/archive/1/474542/100/0/threadedhttp://www.securityfocus.com/bid/24946http://www.securitytracker.com/id?1018414http://www.ubuntu.com/usn/usn-490-1http://www.vupen.com/english/advisories/2007/2564http://www.vupen.com/english/advisories/2007/4256https://exchange.xforce.ibmcloud.com/vulnerabilities/35460https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9875ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txtftp://patches.sgi.com/support/free/security/advisories/20070701-01-P.aschttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://secunia.com/advisories/25589http://secunia.com/advisories/26072http://secunia.com/advisories/26095http://secunia.com/advisories/26103http://secunia.com/advisories/26106http://secunia.com/advisories/26107http://secunia.com/advisories/26149http://secunia.com/advisories/26151http://secunia.com/advisories/26159http://secunia.com/advisories/26179http://secunia.com/advisories/26204http://secunia.com/advisories/26205http://secunia.com/advisories/26211http://secunia.com/advisories/26216http://secunia.com/advisories/26258http://secunia.com/advisories/26271http://secunia.com/advisories/26460http://secunia.com/advisories/28135http://sunsolve.sun.com/search/document.do?assetkey=1-26-103177-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-201516-1http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.htmlhttp://www.debian.org/security/2007/dsa-1337http://www.debian.org/security/2007/dsa-1338http://www.debian.org/security/2007/dsa-1339http://www.gentoo.org/security/en/glsa/glsa-200708-09.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:152http://www.mozilla.org/security/announce/2007/mfsa2007-25.htmlhttp://www.novell.com/linux/security/advisories/2007_49_mozilla.htmlhttp://www.novell.com/linux/security/advisories/2007_57_mozilla.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0722.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0723.htmlhttp://www.redhat.com/support/errata/RHSA-2007-0724.htmlhttp://www.securityfocus.com/archive/1/474226/100/0/threadedhttp://www.securityfocus.com/archive/1/474542/100/0/threadedhttp://www.securityfocus.com/bid/24946http://www.securitytracker.com/id?1018414http://www.ubuntu.com/usn/usn-490-1http://www.vupen.com/english/advisories/2007/2564http://www.vupen.com/english/advisories/2007/4256https://exchange.xforce.ibmcloud.com/vulnerabilities/35460https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9875
2007-07-18
Published