CVE-2007-0009

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
26/02/2007
Last modified:
09/04/2025

Description

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 1.5 (including) 1.5.0.10 (excluding)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 2.0 (including) 2.0.0.2 (excluding)
cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:* 3.11.5 (excluding)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* 1.0.8 (excluding)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* 1.5.0.10 (excluding)
cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools