{"api_version":"1","generated_at":"2026-07-23T10:16:46+00:00","cve":"CVE-2007-3670","urls":{"html":"https://cve.report/CVE-2007-3670","api":"https://cve.report/api/cve/CVE-2007-3670.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3670","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3670"},"summary":{"title":"CVE-2007-3670","description":"Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe.  NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a \"defense in depth\" fix that will \"prevent IE from sending Firefox malicious data.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2007-07-10 19:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/24837","name":"http://www.securityfocus.com/bid/24837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Internet Explorer and Mozilla Firefox URI Handler Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://larholm.com/2007/07/10/internet-explorer-0day-exploit/","name":"http://larholm.com/2007/07/10/internet-explorer-0day-exploit/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Larholm.com - Me, myself and I\t\t\t » Internet Explorer 0day Exploit","mime":"text/html","httpstatus":"500","archivestatus":"200"},{"url":"http://secunia.com/advisories/25984","name":"http://secunia.com/advisories/25984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Firefox \"firefoxurl\" URI Handler Registration Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:152","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:152","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisories | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26204","name":"http://secunia.com/advisories/26204","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Slackware update for thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2473","name":"http://www.vupen.com/english/advisories/2007/2473","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html","name":"http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cross Browser Scripting Demo (with remote command execution)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html","name":"http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security update for MozillaFirefox","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26572","name":"http://secunia.com/advisories/26572","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Ubuntu update for mozilla-thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26216","name":"http://secunia.com/advisories/26216","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE update for MozillaFirefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2007_49_mozilla.html","name":"http://www.novell.com/linux/security/advisories/2007_49_mozilla.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/26271","name":"http://secunia.com/advisories/26271","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE update for MozillaFirefox, MozillaThunderbird, and Seamonkey - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0082","name":"http://www.vupen.com/english/advisories/2008/0082","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018360","name":"http://www.securitytracker.com/id?1018360","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Mozilla Firefox Bugs in URL Protocol Handlers Let Remote Users Execute Arbitrary Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/","name":"http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Issue in URL Protocol Handling on Windows  - Mozilla Security Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-503-1","name":"http://www.ubuntu.com/usn/usn-503-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-503-1: Thunderbird vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28363","name":"http://secunia.com/advisories/28363","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP-UX update for Thunderbird - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-199A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-199A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-199A -- Mozilla Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt","name":"ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2565","name":"http://www.vupen.com/english/advisories/2007/2565","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742","name":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HPSBUX02153 SSRT061181 rev.7 - HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS) - c00771742 - \n\t\tHP Business Support Center","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=565","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=565","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-40.html","name":"http://www.mozilla.org/security/announce/2007/mfsa2007-40.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MFSA 2007-40: Upgraded Thunderbird 1.5.0.13 missing fix for MFSA 2007-23","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26258","name":"http://secunia.com/advisories/26258","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Mandriva update for mozilla-firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579","name":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx","name":"http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Blocking the Firefox -> IE 0-day - Jesper's Blog","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.kb.cert.org/vuls/id/358017","name":"http://www.kb.cert.org/vuls/id/358017","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#358017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35346","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35346","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26149","name":"http://secunia.com/advisories/26149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Slackware update for firefox - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-23.html","name":"http://www.mozilla.org/security/announce/2007/mfsa2007-23.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MFSA 2007-23: Remote code execution by launching Firefox from Internet Explorer","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018351","name":"http://www.securitytracker.com/id?1018351","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Microsoft Internet Explorer Bug in Firefox URL Protocol Handler Lets Remote Users Execute Arbitrary Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26096","name":"http://secunia.com/advisories/26096","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Mozilla Thunderbird Two Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/473276/100/0/threaded","name":"http://www.securityfocus.com/archive/1/473276/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://osvdb.org/38017","name":"http://osvdb.org/38017","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.virusbtn.com/news/virus_news/2007/07_11.xml","name":"http://www.virusbtn.com/news/virus_news/2007/07_11.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Virus Bulletin : \n\t\t\t\tNews - Controversy over IE-to-Firefox exploit","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/4272","name":"http://www.vupen.com/english/advisories/2007/4272","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/","name":"http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"A serious browser vulnerability, but whose? | The Register","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28179","name":"http://secunia.com/advisories/28179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Thunderbird Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3670","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3670","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"6","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7.0","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7.0","cpe7":"beta3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3670","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T14:28:51.407Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-2473","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2473"},{"name":"USN-503-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-503-1"},{"name":"1018360","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018360"},{"name":"1018351","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018351"},{"name":"HPSBUX02156","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/"},{"name":"HPSBUX02153","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"MDKSA-2007:152","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:152"},{"name":"25984","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25984"},{"name":"ie-firefoxurl-command-execution(35346)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35346"},{"name":"TA07-199A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-199A.html"},{"name":"28179","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28179"},{"name":"24837","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24837"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx"},{"name":"26216","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26216"},{"name":"SSRT061236","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.virusbtn.com/news/virus_news/2007/07_11.xml"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/"},{"name":"20070719 Multiple Vendor Multiple Product URI Handler Input Validation Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=565"},{"name":"ADV-2007-2565","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2565"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-40.html"},{"name":"26149","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26149"},{"name":"ADV-2008-0082","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0082"},{"name":"38017","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/38017"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-23.html"},{"name":"VU#358017","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/358017"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html"},{"name":"ADV-2007-4272","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/4272"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://larholm.com/2007/07/10/internet-explorer-0day-exploit/"},{"name":"SUSE-SA:2007:049","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2007_49_mozilla.html"},{"name":"SSRT061181","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt"},{"name":"20070710 Internet Explorer 0day exploit","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html"},{"name":"26258","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26258"},{"name":"28363","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28363"},{"name":"20070710 Internet Explorer 0day exploit","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/473276/100/0/threaded"},{"name":"26271","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26271"},{"name":"26204","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26204"},{"name":"26572","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26572"},{"name":"26096","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26096"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe.  NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a \"defense in depth\" fix that will \"prevent IE from sending Firefox malicious data.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2007-2473","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2473"},{"name":"USN-503-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-503-1"},{"name":"1018360","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018360"},{"name":"1018351","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018351"},{"name":"HPSBUX02156","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579"},{"tags":["x_refsource_MISC"],"url":"http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/"},{"name":"HPSBUX02153","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"MDKSA-2007:152","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:152"},{"name":"25984","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25984"},{"name":"ie-firefoxurl-command-execution(35346)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35346"},{"name":"TA07-199A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-199A.html"},{"name":"28179","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28179"},{"name":"24837","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24837"},{"tags":["x_refsource_MISC"],"url":"http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx"},{"name":"26216","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26216"},{"name":"SSRT061236","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579"},{"tags":["x_refsource_MISC"],"url":"http://www.virusbtn.com/news/virus_news/2007/07_11.xml"},{"tags":["x_refsource_MISC"],"url":"http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/"},{"name":"20070719 Multiple Vendor Multiple Product URI Handler Input Validation Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=565"},{"name":"ADV-2007-2565","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2565"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-40.html"},{"name":"26149","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26149"},{"name":"ADV-2008-0082","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0082"},{"name":"38017","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/38017"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mozilla.org/security/announce/2007/mfsa2007-23.html"},{"name":"VU#358017","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/358017"},{"tags":["x_refsource_MISC"],"url":"http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html"},{"name":"ADV-2007-4272","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/4272"},{"tags":["x_refsource_MISC"],"url":"http://larholm.com/2007/07/10/internet-explorer-0day-exploit/"},{"name":"SUSE-SA:2007:049","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2007_49_mozilla.html"},{"name":"SSRT061181","tags":["vendor-advisory","x_refsource_HP"],"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"tags":["x_refsource_CONFIRM"],"url":"ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt"},{"name":"20070710 Internet Explorer 0day exploit","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html"},{"name":"26258","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26258"},{"name":"28363","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28363"},{"name":"20070710 Internet Explorer 0day exploit","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/473276/100/0/threaded"},{"name":"26271","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26271"},{"name":"26204","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26204"},{"name":"26572","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26572"},{"name":"26096","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26096"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-3670","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe.  NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a \"defense in depth\" fix that will \"prevent IE from sending Firefox malicious data.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-2473","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2473"},{"name":"USN-503-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-503-1"},{"name":"1018360","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018360"},{"name":"1018351","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018351"},{"name":"HPSBUX02156","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579"},{"name":"http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/","refsource":"MISC","url":"http://blog.mozilla.com/security/2007/07/10/security-issue-in-url-protocol-handling-on-windows/"},{"name":"HPSBUX02153","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"MDKSA-2007:152","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:152"},{"name":"25984","refsource":"SECUNIA","url":"http://secunia.com/advisories/25984"},{"name":"ie-firefoxurl-command-execution(35346)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35346"},{"name":"TA07-199A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-199A.html"},{"name":"28179","refsource":"SECUNIA","url":"http://secunia.com/advisories/28179"},{"name":"24837","refsource":"BID","url":"http://www.securityfocus.com/bid/24837"},{"name":"http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx","refsource":"MISC","url":"http://msinfluentials.com/blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx"},{"name":"26216","refsource":"SECUNIA","url":"http://secunia.com/advisories/26216"},{"name":"SSRT061236","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00774579"},{"name":"http://www.virusbtn.com/news/virus_news/2007/07_11.xml","refsource":"MISC","url":"http://www.virusbtn.com/news/virus_news/2007/07_11.xml"},{"name":"http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/","refsource":"MISC","url":"http://www.theregister.co.uk/2007/07/11/ie_firefox_vuln/"},{"name":"20070719 Multiple Vendor Multiple Product URI Handler Input Validation Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=565"},{"name":"ADV-2007-2565","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2565"},{"name":"http://www.mozilla.org/security/announce/2007/mfsa2007-40.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2007/mfsa2007-40.html"},{"name":"26149","refsource":"SECUNIA","url":"http://secunia.com/advisories/26149"},{"name":"ADV-2008-0082","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0082"},{"name":"38017","refsource":"OSVDB","url":"http://osvdb.org/38017"},{"name":"http://www.mozilla.org/security/announce/2007/mfsa2007-23.html","refsource":"CONFIRM","url":"http://www.mozilla.org/security/announce/2007/mfsa2007-23.html"},{"name":"VU#358017","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/358017"},{"name":"http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html","refsource":"MISC","url":"http://www.xs-sniper.com/sniperscope/IE-Pwns-Firefox.html"},{"name":"ADV-2007-4272","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/4272"},{"name":"http://larholm.com/2007/07/10/internet-explorer-0day-exploit/","refsource":"MISC","url":"http://larholm.com/2007/07/10/internet-explorer-0day-exploit/"},{"name":"SUSE-SA:2007:049","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2007_49_mozilla.html"},{"name":"SSRT061181","refsource":"HP","url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742"},{"name":"ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt","refsource":"CONFIRM","url":"ftp://ftp.slackware.com/pub/slackware/slackware-12.0/ChangeLog.txt"},{"name":"20070710 Internet Explorer 0day exploit","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0160.html"},{"name":"http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html","refsource":"CONFIRM","url":"http://support.novell.com/techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html"},{"name":"26258","refsource":"SECUNIA","url":"http://secunia.com/advisories/26258"},{"name":"28363","refsource":"SECUNIA","url":"http://secunia.com/advisories/28363"},{"name":"20070710 Internet Explorer 0day exploit","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/473276/100/0/threaded"},{"name":"26271","refsource":"SECUNIA","url":"http://secunia.com/advisories/26271"},{"name":"26204","refsource":"SECUNIA","url":"http://secunia.com/advisories/26204"},{"name":"26572","refsource":"SECUNIA","url":"http://secunia.com/advisories/26572"},{"name":"26096","refsource":"SECUNIA","url":"http://secunia.com/advisories/26096"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-3670","datePublished":"2007-07-10T19:00:00.000Z","dateReserved":"2007-07-10T00:00:00.000Z","dateUpdated":"2024-08-07T14:28:51.407Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-10 19:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*","matchCriteriaId":"693D3C1C-E3E4-49DB-9A13-44ADDFF82507"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*","matchCriteriaId":"D47247A3-7CD7-4D67-9D9B-A94A504DA1BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:*","matchCriteriaId":"6BC71FD8-D385-4507-BD14-B75FDD4C79E6"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:*","matchCriteriaId":"ED471260-0272-431F-A91E-AC2883D92497"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7.0:beta2:*:*:*:*:*:*","matchCriteriaId":"63D18070-EC48-4904-9AE0-558F7F3B869D"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7.0:beta3:*:*:*:*:*:*","matchCriteriaId":"86584E3F-3B0D-4018-A186-E59F3B01CA5C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*","matchCriteriaId":"14E6A30E-7577-4569-9309-53A0AF7FE3AC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3670","Ordinal":"1","Title":"CVE-2007-3670","CVE":"CVE-2007-3670","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3670","Ordinal":"1","NoteData":"Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe.  NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a \"defense in depth\" fix that will \"prevent IE from sending Firefox malicious data.\"","Type":"Description","Title":"CVE-2007-3670"},{"CveYear":"2007","CveId":"3670","Ordinal":"2","NoteData":"2007-07-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3670","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}