CVE-2007-4879
published 2007-09-13CVE-2007-4879: Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and…
PriorityP417medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.27%
66.6th percentile
Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 2.0.0.12 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5r28-wf7x-cq3h: CFNetwork in Safari in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2008-1580 [MEDIUM] CWE-200 GHSA-5r28-wf7x-cq3h: CFNetwork in Safari in Apple Mac OS X before 10
CFNetwork in Safari in Apple Mac OS X before 10.5.3 automatically sends an SSL client certificate in response to a web server's certificate request, which allows remote web sites to obtain sensitive information (Subject data) from personally identifiable certificates, and use arbitrary certificates to track user activities across domains, a related issue to CVE-2007-4879.
GHSA
GHSA-p6j7-wg3q-q2c3: Mozilla Firefox before Firefox 2
ghsa_unreviewed·2022-05-01
CVE-2007-4879 [MEDIUM] GHSA-p6j7-wg3q-q2c3: Mozilla Firefox before Firefox 2
Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2008-03-26·CVSS 5.0
CVE-2008-1241 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox vulnerabilities
Alexey Proskuryakov, Yosuke Hasegawa and Simon Montagu discovered flaws
in Firefox's character encoding handling. If a user were tricked into
opening a malicious web page, an attacker could perform cross-site
scripting attacks. (CVE-2008-0416)
Various flaws were discovered in the JavaScript engine. By tricking
a user into opening a malicious web page, an attacker could escalate
privileges within the browser, perform cross-site scripting attacks
and/or execute arbitrary code with the user's privileges.
(CVE-2008-1233, CVE-2008-1234, CVE-2008-1235)
Several problems were discovered in Firefox which could lead to crashes
and memory corruption. If a user were tricked into opening a malicious
web page, an attacker may be able to
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://0x90.eu/ff_tls_poc.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlhttp://secunia.com/advisories/29526http://secunia.com/advisories/29539http://secunia.com/advisories/29541http://secunia.com/advisories/29547http://secunia.com/advisories/29558http://secunia.com/advisories/29560http://secunia.com/advisories/29616http://secunia.com/advisories/29645http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128http://www.debian.org/security/2008/dsa-1532http://www.debian.org/security/2008/dsa-1534http://www.debian.org/security/2008/dsa-1535http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:080http://www.mozilla.org/security/announce/2008/mfsa2008-17.htmlhttp://www.securityfocus.com/archive/1/490196/100/0/threadedhttp://www.securityfocus.com/bid/28448http://www.securitytracker.com/id?1019704http://www.ubuntu.com/usn/usn-592-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/0998/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=395399http://0x90.eu/ff_tls_poc.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00002.htmlhttp://secunia.com/advisories/29526http://secunia.com/advisories/29539http://secunia.com/advisories/29541http://secunia.com/advisories/29547http://secunia.com/advisories/29558http://secunia.com/advisories/29560http://secunia.com/advisories/29616http://secunia.com/advisories/29645http://secunia.com/advisories/30327http://secunia.com/advisories/30620http://sunsolve.sun.com/search/document.do?assetkey=1-26-238492-1http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0128http://www.debian.org/security/2008/dsa-1532http://www.debian.org/security/2008/dsa-1534http://www.debian.org/security/2008/dsa-1535http://www.gentoo.org/security/en/glsa/glsa-200805-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:080http://www.mozilla.org/security/announce/2008/mfsa2008-17.htmlhttp://www.securityfocus.com/archive/1/490196/100/0/threadedhttp://www.securityfocus.com/bid/28448http://www.securitytracker.com/id?1019704http://www.ubuntu.com/usn/usn-592-1http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlhttp://www.vupen.com/english/advisories/2008/0998/referenceshttp://www.vupen.com/english/advisories/2008/1793/referenceshttps://bugzilla.mozilla.org/show_bug.cgi?id=395399
2007-09-13
Published