Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2007 27 | — | Upgrade to Mozilla Firefox version 2.0.0.6 | Jun 14, 2012 | Aug 7, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.4 | Feb 3, 2012 | Aug 7, 2007 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.6Upgrade to Mozilla Thunderbird version 1.5.0.13 | Feb 22, 2012 | Aug 7, 2007 |
| Suse | — | Upgrade MozillaFirefox-translationsUpgrade seamonkey-dom-inspectorUpgrade MozillaFirefoxUpgrade seamonkey-ircUpgrade mozilla-ircUpgrade mozilla-venkmanUpgrade mozilla-dom-inspectorUpgrade mozilla-develUpgrade mozilla-huUpgrade mozilla-deatUpgrade seamonkey-mailUpgrade seamonkey-spellcheckerUpgrade seamonkeyUpgrade mozilla-mailUpgrade suse-releaseUpgrade mozillaUpgrade seamonkey-venkmanUpgrade mozilla-calendarUpgrade mozilla-cs | Feb 17, 2015 | Aug 7, 2007 |
| Ubuntu | — | Upgrade firefoxUpgrade mozilla-thunderbird | Nov 8, 2024 | Aug 8, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub