// For flags

CVE-2007-3656

 

Severity Score

6.8
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.

Mozilla Firefox versiones anteriores a 1.8.0.13 y 1.8.1.x versiones anteriores a 1.8.1.5 no realiza comprobaciones de seguridad de zona cuando procesa un wyciwyg URI, lo cual permite a atacantes remotos obtener información confidencial, envenenar la caché de navegador, y posiblemente habilitar posteriores vectores de ataque mediante (1) controles de redirección HTTP 302, (2) XMLHttpRequest, ó (3) URIs de ver-código-fuente.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-07-10 CVE Reserved
  • 2007-07-10 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2024-10-13 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (47)
URL Tag Source
ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt X_refsource_confirm
http://osvdb.org/38028 Vdb Entry
http://secunia.com/advisories/25589 Third Party Advisory
http://secunia.com/advisories/25990 Third Party Advisory
http://secunia.com/advisories/26072 Third Party Advisory
http://secunia.com/advisories/26103 Third Party Advisory
http://secunia.com/advisories/26107 Third Party Advisory
http://secunia.com/advisories/26149 Third Party Advisory
http://secunia.com/advisories/26151 Third Party Advisory
http://secunia.com/advisories/26159 Third Party Advisory
http://secunia.com/advisories/26179 Third Party Advisory
http://secunia.com/advisories/26204 Third Party Advisory
http://secunia.com/advisories/26205 Third Party Advisory
http://secunia.com/advisories/26211 Third Party Advisory
http://secunia.com/advisories/26216 Third Party Advisory
http://secunia.com/advisories/26258 Third Party Advisory
http://secunia.com/advisories/26271 Third Party Advisory
http://secunia.com/advisories/26460 Third Party Advisory
http://secunia.com/advisories/28135 Third Party Advisory
http://securityreason.com/securityalert/2872 Third Party Advisory
http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html X_refsource_confirm
http://www.mozilla.org/security/announce/2007/mfsa2007-24.html X_refsource_confirm
http://www.securityfocus.com/archive/1/473191/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/474226/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/474542/100/0/threaded Mailing List
http://www.securityfocus.com/bid/24831 Vdb Entry
http://www.securitytracker.com/id?1018411 Vdb Entry
http://www.vupen.com/english/advisories/2007/4256 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35298 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9105 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0
Search vendor "Mozilla" for product "Firefox" and version "1.0"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.1
Search vendor "Mozilla" for product "Firefox" and version "1.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.2
Search vendor "Mozilla" for product "Firefox" and version "1.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.3
Search vendor "Mozilla" for product "Firefox" and version "1.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.4
Search vendor "Mozilla" for product "Firefox" and version "1.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.5
Search vendor "Mozilla" for product "Firefox" and version "1.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.6
Search vendor "Mozilla" for product "Firefox" and version "1.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.7
Search vendor "Mozilla" for product "Firefox" and version "1.0.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.0.8
Search vendor "Mozilla" for product "Firefox" and version "1.0.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5
Search vendor "Mozilla" for product "Firefox" and version "1.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.1
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.2
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.3
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.4
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.5
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.6
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.7
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.8
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.9
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.9"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.10
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.10"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.11
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.11"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.0.12
Search vendor "Mozilla" for product "Firefox" and version "1.5.0.12"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.1
Search vendor "Mozilla" for product "Firefox" and version "1.5.1"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.2
Search vendor "Mozilla" for product "Firefox" and version "1.5.2"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.3
Search vendor "Mozilla" for product "Firefox" and version "1.5.3"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.4
Search vendor "Mozilla" for product "Firefox" and version "1.5.4"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.5
Search vendor "Mozilla" for product "Firefox" and version "1.5.5"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.6
Search vendor "Mozilla" for product "Firefox" and version "1.5.6"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.7
Search vendor "Mozilla" for product "Firefox" and version "1.5.7"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.5.8
Search vendor "Mozilla" for product "Firefox" and version "1.5.8"
-
Affected
Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
1.8
Search vendor "Mozilla" for product "Firefox" and version "1.8"
-
Affected