CVE-2007-4879
Last modified
CVE-2007-4879 is a vulnerability of currently unknown severity. Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 2.0.0.12 |
| Mozilla | Firefox | 0.1 |
| Mozilla | Firefox | 0.2 |
| Mozilla | Firefox | 0.3 |
| Mozilla | Firefox | 0.4 |
| Mozilla | Firefox | 0.5 |
| Mozilla | Firefox | 0.6 |
| Mozilla | Firefox | 0.6.1 |
| Mozilla | Firefox | 0.7 |
| Mozilla | Firefox | 0.7.1 |
| Mozilla | Firefox | 0.8 |
| Mozilla | Firefox | 0.9 |
| Mozilla | Firefox | 0.9.1 |
| Mozilla | Firefox | 0.9.2 |
| Mozilla | Firefox | 0.9.3 |
| Mozilla | Firefox | 0.10 |
| Mozilla | Firefox | 0.10.1 |
| Mozilla | Firefox | 1.0 |
| Mozilla | Firefox | 1.0.1 |
| Mozilla | Firefox | 1.0.2 |
| Mozilla | Firefox | 1.0.3 |
| Mozilla | Firefox | 1.0.4 |
| Mozilla | Firefox | 1.0.5 |
| Mozilla | Firefox | 1.0.6 |
| Mozilla | Firefox | 1.0.7 |
| Mozilla | Firefox | 1.0.8 |
| Mozilla | Firefox | 1.4.1 |
| Mozilla | Firefox | 1.5 |
| Mozilla | Firefox | 1.5.0.1 |
| Mozilla | Firefox | 1.5.0.2 |
| Mozilla | Firefox | 1.5.0.3 |
| Mozilla | Firefox | 1.5.0.4 |
| Mozilla | Firefox | 1.5.0.5 |
| Mozilla | Firefox | 1.5.0.6 |
| Mozilla | Firefox | 1.5.0.7 |
| Mozilla | Firefox | 1.5.0.8 |
| Mozilla | Firefox | 1.5.0.9 |
| Mozilla | Firefox | 1.5.0.10 |
| Mozilla | Firefox | 1.5.0.11 |
| Mozilla | Firefox | 1.5.0.12 |
| Mozilla | Firefox | 1.5.1 |
| Mozilla | Firefox | 1.5.2 |
| Mozilla | Firefox | 1.5.3 |
| Mozilla | Firefox | 1.5.4 |
| Mozilla | Firefox | 1.5.5 |
| Mozilla | Firefox | 1.5.6 |
| Mozilla | Firefox | 1.5.7 |
| Mozilla | Firefox | 1.5.8 |
| Mozilla | Firefox | 1.8 |
| Mozilla | Firefox | 2.0 |
Showing 50 of 80 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/29526Vendor Advisory
- http://secunia.com/advisories/29539Vendor Advisory
- http://secunia.com/advisories/29541Vendor Advisory
- http://secunia.com/advisories/29547Vendor Advisory
- http://secunia.com/advisories/29558Vendor Advisory
- http://secunia.com/advisories/29560Vendor Advisory
- http://secunia.com/advisories/29616Vendor Advisory
- http://secunia.com/advisories/29645Vendor Advisory
- http://secunia.com/advisories/30327Vendor Advisory
- http://secunia.com/advisories/30620Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0998/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1793/referencesVendor Advisory
- http://secunia.com/advisories/29526Vendor Advisory
- http://secunia.com/advisories/29539Vendor Advisory
- http://secunia.com/advisories/29541Vendor Advisory
- http://secunia.com/advisories/29547Vendor Advisory
- http://secunia.com/advisories/29558Vendor Advisory
- http://secunia.com/advisories/29560Vendor Advisory
- http://secunia.com/advisories/29616Vendor Advisory
- http://secunia.com/advisories/29645Vendor Advisory
- http://secunia.com/advisories/30327Vendor Advisory
- http://secunia.com/advisories/30620Vendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-087A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0998/referencesVendor Advisory
- http://www.vupen.com/english/advisories/2008/1793/referencesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4879?
How severe is CVE-2007-4879?
How do I fix CVE-2007-4879?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4861SAXON 5.4, with display_errors enabled, allows remote attack…
- CVE-2007-4862Cross-site scripting (XSS) vulnerability in admin/menu.php i…
- CVE-2007-4863SQL injection vulnerability in example.php in SAXON 5.4 allo…
- CVE-2007-4872SimpNews 2.41.03 allows remote attackers to obtain sensitive…
- CVE-2007-4873SimpNews 2.41.03 stores sensitive information under the web …
- CVE-2007-4874Multiple cross-site scripting (XSS) vulnerabilities in SimpN…
- CVE-2007-4880Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.…
- CVE-2007-4881SQL injection vulnerability in profile/myprofile.php in psi-…
- CVE-2007-4882Multiple cross-site scripting (XSS) vulnerabilities in TechE…
- CVE-2007-4883Cross-site scripting (XSS) vulnerability in the BotQuery ext…
- CVE-2007-4884Media Player Classic (MPC) allows user-assisted remote attac…
- CVE-2007-4885Avnex AV MP3 Player allows user-assisted remote attackers to…
Are you affected by CVE-2007-4879?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
