CVE-2007-0009
Last modified
CVE-2007-0009 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.. EPSS estimates a 50.36% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | >= 1.5, < 1.5.0.10 |
| Mozilla | Firefox | >= 2.0, < 2.0.0.2 |
| Mozilla | Network Security Services | < 3.11.5 |
| Mozilla | Seamonkey | < 1.0.8 |
| Mozilla | Thunderbird | < 1.5.0.10 |
| Debian | Debian Linux | 3.1 |
| Debian | Debian Linux | 4.0 |
| Canonical | Ubuntu Linux | 5.10 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
References
- http://fedoranews.org/cms/node/2709Broken Link
- http://fedoranews.org/cms/node/2711Broken Link
- http://fedoranews.org/cms/node/2747Broken Link
- http://fedoranews.org/cms/node/2749Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlThird Party Advisory
- http://secunia.com/advisories/24253Third Party Advisory
- http://secunia.com/advisories/24277Third Party Advisory
- http://secunia.com/advisories/24287Third Party Advisory
- http://secunia.com/advisories/24290Third Party Advisory
- http://secunia.com/advisories/24293Third Party Advisory
- http://secunia.com/advisories/24333Third Party Advisory
- http://secunia.com/advisories/24342Third Party Advisory
- http://secunia.com/advisories/24343Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24389Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24406Third Party Advisory
- http://secunia.com/advisories/24410Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24456Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24522Third Party Advisory
- http://secunia.com/advisories/24562Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/24703Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://secunia.com/advisories/25597Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200703-18.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200703-22.xmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/592796Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:050Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:052Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlThird Party Advisory
- http://www.osvdb.org/32106Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/461336/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/461809/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017696Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-428-1Third Party Advisory
- http://www.ubuntu.com/usn/usn-431-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0718Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0719Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1165Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2141Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=364323Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32663Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1081Broken Link
- https://issues.rpath.com/browse/RPL-1103Broken Link
- http://fedoranews.org/cms/node/2709Broken Link
- http://fedoranews.org/cms/node/2711Broken Link
- http://fedoranews.org/cms/node/2747Broken Link
- http://fedoranews.org/cms/node/2749Broken Link
- http://rhn.redhat.com/errata/RHSA-2007-0077.htmlThird Party Advisory
- http://secunia.com/advisories/24253Third Party Advisory
- http://secunia.com/advisories/24277Third Party Advisory
- http://secunia.com/advisories/24287Third Party Advisory
- http://secunia.com/advisories/24290Third Party Advisory
- http://secunia.com/advisories/24293Third Party Advisory
- http://secunia.com/advisories/24333Third Party Advisory
- http://secunia.com/advisories/24342Third Party Advisory
- http://secunia.com/advisories/24343Third Party Advisory
- http://secunia.com/advisories/24384Third Party Advisory
- http://secunia.com/advisories/24389Third Party Advisory
- http://secunia.com/advisories/24395Third Party Advisory
- http://secunia.com/advisories/24406Third Party Advisory
- http://secunia.com/advisories/24410Third Party Advisory
- http://secunia.com/advisories/24455Third Party Advisory
- http://secunia.com/advisories/24456Third Party Advisory
- http://secunia.com/advisories/24457Third Party Advisory
- http://secunia.com/advisories/24522Third Party Advisory
- http://secunia.com/advisories/24562Third Party Advisory
- http://secunia.com/advisories/24650Third Party Advisory
- http://secunia.com/advisories/24703Third Party Advisory
- http://secunia.com/advisories/25588Third Party Advisory
- http://secunia.com/advisories/25597Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200703-18.xmlThird Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947Mailing List, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851Mailing List, Third Party Advisory
- http://www.debian.org/security/2007/dsa-1336Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200703-22.xmlThird Party Advisory
- http://www.kb.cert.org/vuls/id/592796Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:050Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:052Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlThird Party Advisory
- http://www.osvdb.org/32106Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-0078.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0079.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0097.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0108.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/461336/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/461809/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1017696Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-428-1Third Party Advisory
- http://www.ubuntu.com/usn/usn-431-1Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0718Third Party Advisory
- http://www.vupen.com/english/advisories/2007/0719Third Party Advisory
- http://www.vupen.com/english/advisories/2007/1165Third Party Advisory
- http://www.vupen.com/english/advisories/2007/2141Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=364323Issue Tracking, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32663Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1081Broken Link
- https://issues.rpath.com/browse/RPL-1103Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0009?
How severe is CVE-2007-0009?
How do I fix CVE-2007-0009?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-0003pam_unix.so in Linux-PAM 0.99.7.0 allows context-dependent a…
- CVE-2007-0004The NFS client implementation in the kernel in Red Hat Enter…
- CVE-2007-0005Multiple buffer overflows in the (1) read and (2) write hand…
- CVE-2007-0006The key serial number collision avoidance code in the key_al…
- CVE-2007-0007gnucash 2.0.4 and earlier allows local users to overwrite ar…
- CVE-2007-0008Integer underflow in the SSLv2 support in Mozilla Network Se…
- CVE-2007-0010The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2…
- CVE-2007-0011The web portal interface in Citrix Access Gateway (aka Citri…
- CVE-2007-0012Sun JRE 5.0 before update 14 allows remote attackers to caus…
- CVE-2007-0014ChainKey Java Code Protection allows attackers to decompile …
- CVE-2007-0015Buffer overflow in Apple QuickTime 7.1.3 allows remote attac…
- CVE-2007-0016Stack-based buffer overflow in MoviePlay 4.76 allows remote …
Are you affected by CVE-2007-0009?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
