CVE-2007-5337

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 5.53 % (93th)
5.53% Progress
Affected Products 4
Advisories 8

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

Weaknesses
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2007-10-21 20:17:00
(17 years ago)
Updated Date
2018-10-15 21:43:03
(6 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Linux Kernel cpe:2.3:o:linux:linux_kernel
OR  
  Running on/with
  Gnome-vfs cpe:2.3:a:gnome:gnome-vfs
OR  
  Running on/with
  Mozilla Firefox 2.0.0.7 and prior versions cpe:2.3:a:mozilla:firefox <= 2.0.0.7
OR  
  Running on/with
  Mozilla Seamonkey 1.1.4 and prior versions cpe:2.3:a:mozilla:seamonkey <= 1.1.4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...