CVE-2007-4038
published 2007-07-27CVE-2007-4038: Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.11%
62.7th percentile
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking Thunderbird.exe, a similar issue to CVE-2007-3670.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.4 | — |
| mozilla | thunderbird | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3r6g-vgfw-328v: Argument injection vulnerability in Mozilla Firefox before 2
ghsa_unreviewed·2022-05-01·CVSS 4.3
CVE-2007-4038 [MEDIUM] CWE-94 GHSA-3r6g-vgfw-328v: Argument injection vulnerability in Mozilla Firefox before 2
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking Thunderbird.exe, a similar issue to CVE-2007-3670.
Red Hat
CVE-2007-4038: Argument injection vulnerability in Mozilla Firefox before 2
vendor_redhat·CVSS 4.3
CVE-2007-4038 [MEDIUM] CVE-2007-4038: Argument injection vulnerability in Mozilla Firefox before 2
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking Thunderbird.exe, a similar issue to CVE-2007-3670.
Statement: Not vulnerable. This issue does not affect the versions of Firefox or Thunderbird as shipped with Red Hat Enterprise Linux.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://larholm.com/2007/07/25/mozilla-protocol-abuse/http://seclists.org/fulldisclosure/2007/Jul/0557.htmlhttp://www.securityfocus.com/archive/1/474624/100/0/threadedhttp://www.securityfocus.com/archive/1/474686/100/0/threadedhttp://larholm.com/2007/07/25/mozilla-protocol-abuse/http://seclists.org/fulldisclosure/2007/Jul/0557.htmlhttp://www.securityfocus.com/archive/1/474624/100/0/threadedhttp://www.securityfocus.com/archive/1/474686/100/0/threaded
2007-07-27
Published