CVE-2007-3738Off-by-one Error in Mozilla Firefox

CWE-193Off-by-one Error8 documents6 sources
Severity
9.3CRITICALNVD
EPSS
15.7%
top 5.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Latest updateMay 3

Description

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDmozilla/firefox5 versions+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-p4qw-x342-xjwx: Multiple unspecified vulnerabilities in Mozilla Firefox before 22022-05-03

📋Vendor Advisories

3
Red Hat
openssl: SSL_get_shared_ciphers() off-by-one2007-09-27
Ubuntu
Firefox vulnerabilities2007-07-20
Red Hat
security flaw2007-07-18

💬Community

2
Bugzilla
CVE-2007-3738 security flaw2018-08-16
Bugzilla
CVE-2007-3089 various flaws in mozilla products (CVE-2007-3734 CVE-2007-3735 CVE-2007-3736 CVE-2007-3737 CVE-2007-3656 CVE-2007-3738)2007-07-17