Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5337

Опубликовано: 21 окт. 2007
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Одно из

cpe:2.3:a:gnome:gnome-vfs:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 2.0.0.7 (включая)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:*
Версия до 1.1.4 (включая)

EPSS

Процентиль: 79%
0.01383
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 17 лет назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

redhat
больше 17 лет назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

debian
больше 17 лет назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when runnin ...

github
около 3 лет назад

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

oracle-oval
больше 17 лет назад

ELSA-2007-0979: Critical: firefox security update (CRITICAL)

EPSS

Процентиль: 79%
0.01383
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-200
Уязвимость CVE-2007-5337