CVE-2007-3150
Last modified
CVE-2007-3150 is a vulnerability of currently unknown severity. Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file, which is displayed in the "results stored on your computer" portion of the search results, and when clicked invokes Google Desktop to execute this file.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file, which is displayed in the "results stored on your computer" portion of the search results, and when clicked invokes Google Desktop to execute this file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Desktop | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-3150?
How severe is CVE-2007-3150?
How do I fix CVE-2007-3150?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-3144Visual truncation vulnerability in Mozilla 1.7.12 allows rem…
- CVE-2007-3145Visual truncation vulnerability in Galeon 2.0.1 allows remot…
- CVE-2007-3146Zen Help Desk 2.1 stores sensitive information under the web…
- CVE-2007-3147Buffer overflow in the Yahoo! Webcam Upload ActiveX control …
- CVE-2007-3148Buffer overflow in the Yahoo! Webcam Viewer ActiveX control …
- CVE-2007-3149sudo, when linked with MIT Kerberos 5 (krb5), does not prope…
- CVE-2007-3151rpttop.htm in the web management interface in Packeteer Pack…
- CVE-2007-3152c-ares before 1.4.0 uses a predictable seed for the random n…
- CVE-2007-3153The ares_init:randomize_key function in c-ares, on platforms…
- CVE-2007-3154Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka …
- CVE-2007-3155Unspecified vulnerability in eGroupWare before 1.2.107-2 has…
- CVE-2007-3156Multiple cross-site scripting (XSS) vulnerabilities in pam_l…
Are you affected by CVE-2007-3150?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
