CVE-2007-3073: High severity Apple iOS and macOS vulnerability
Published Jun 6, 2007
·Updated
Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.
Affected Software
43 affected components
Apple iOS and macOS
Apple iOS and macOS=10.0
Apple iOS and macOS=10.0.1
Apple iOS and macOS=10.0.2
Apple iOS and macOS=10.0.3
Apple iOS and macOS=10.0.4
Apple iOS and macOS=10.1
Apple iOS and macOS=10.1.1
Apple iOS and macOS=10.1.2
Apple iOS and macOS=10.1.3
Apple iOS and macOS=10.1.4
Apple iOS and macOS=10.1.5
Apple iOS and macOS=10.2
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.2.2
Apple iOS and macOS=10.2.3
Apple iOS and macOS=10.2.4
Apple iOS and macOS=10.2.5
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple iOS and macOS=10.3.7
Apple iOS and macOS=10.3.8
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.1
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.4.9
Unix Unix
Mozilla Firefox<=2.0.0.4
Event History
Jun 6, 2007
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2007-3073?
CVE-2007-3073 has a medium severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2007-3073?
To resolve CVE-2007-3073, update Mozilla Firefox to version 2.0.0.5 or later.
3
Which versions of Firefox are affected by CVE-2007-3073?
CVE-2007-3073 affects Mozilla Firefox versions prior to 2.0.0.5.
4
What is the impact of CVE-2007-3073?
CVE-2007-3073 allows remote attackers to read arbitrary files on the system.
5
Is CVE-2007-3073 applicable to all operating systems?
CVE-2007-3073 specifically affects Mozilla Firefox on Mac OS X and Unix systems.