CVE-2007-3738: Critical severity Mozilla Firefox vulnerability
Published Jul 18, 2007
·Updated
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
Affected Software
5 affected components
Mozilla Firefox=2.0
Mozilla Firefox=2.0.0.1
Mozilla Firefox=2.0.0.2
Mozilla Firefox=2.0.0.3
Mozilla Firefox=2.0.0.4
Remediation
Patch Available
Event History
Jul 18, 2007
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
Which Firefox installations are affected?
Mozilla Firefox versions before 2.0.0.5 are affected. The issue is remotely exploitable and does not require authentication.
2
What does an attacker need to do to exploit this vulnerability?
An attacker needs to induce the target to process a crafted XPCNativeWrapper. Successful exploitation can result in arbitrary code execution with impacts to confidentiality, integrity, and availability.
3
Is a patch available?
Yes. A patch is available; update Firefox to a version that is not before 2.0.0.5.