CVE-2007-3670
Summary
| CVE | CVE-2007-3670 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-10 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Internet Explorer | 6 | All | All | All |
| Application | Microsoft | Internet Explorer | 6 | sp1 | All | All |
| Application | Microsoft | Internet Explorer | 7.0 | All | All | All |
| Application | Microsoft | Internet Explorer | 7.0 | beta1 | All | All |
| Application | Microsoft | Internet Explorer | 7.0 | beta2 | All | All |
| Application | Microsoft | Internet Explorer | 7.0 | beta3 | All | All |
| Application | Mozilla | Firefox | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Larholm.com - Me, myself and I » Internet Explorer 0day Exploit | af854a3a-2127-422b-91ae-364da2661108 | larholm.com | |
| Firefox "firefoxurl" URI Handler Registration Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Advisories | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Slackware update for thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Cross Browser Scripting Demo (with remote command execution) | af854a3a-2127-422b-91ae-364da2661108 | www.xs-sniper.com | |
| Security update for MozillaFirefox | af854a3a-2127-422b-91ae-364da2661108 | support.novell.com | |
| Ubuntu update for mozilla-thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SUSE update for MozillaFirefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityTracker.com Archives - Mozilla Firefox Bugs in URL Protocol Handlers Let Remote Users Execute Arbitrary Commands | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Security Issue in URL Protocol Handling on Windows - Mozilla Security Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.mozilla.com | |
| USN-503-1: Thunderbird vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| HP-UX update for Thunderbird - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| US-CERT Technical Cyber Security Alert TA07-199A -- Mozilla Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt | af854a3a-2127-422b-91ae-364da2661108 | ftp.slackware.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| HPSBUX02153 SSRT061181 rev.7 - HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) - c00771742 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| labs.idefense.com/intelligence/vulnerabilities/display.php | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | |
| MFSA 2007-40: Upgraded Thunderbird 1.5.0.13 missing fix for MFSA 2007-23 | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| Mandriva update for mozilla-firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| Blocking the Firefox -> IE 0-day - Jesper's Blog | af854a3a-2127-422b-91ae-364da2661108 | msinfluentials.com | |
| archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| US-CERT Vulnerability Note VU#358017 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Slackware update for firefox - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| MFSA 2007-23: Remote code execution by launching Firefox from Internet Explorer | af854a3a-2127-422b-91ae-364da2661108 | www.mozilla.org | |
| SecurityTracker.com Archives - Microsoft Internet Explorer Bug in Firefox URL Protocol Handler Lets Remote Users Execute Arbitrary Commands | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Mozilla Thunderbird Two Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/38017 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Virus Bulletin : News - Controversy over IE-to-Firefox exploit | af854a3a-2127-422b-91ae-364da2661108 | www.virusbtn.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| A serious browser vulnerability, but whose? | The Register | af854a3a-2127-422b-91ae-364da2661108 | www.theregister.co.uk | |
| Thunderbird Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.