← Back to browse · API

CVE-2007-4039

Severity
CRITICAL
CVSS
9.8
EPSS
0.02014
Risk score
39.9
CISA KEV
No
PoC
No
Published
2007-07-27
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2007-4023, GHSA-5QRV-2VJC-XWCQ
Products
n/a:n/a n/a
Sources
euvd EUVD-2007-4023

Description

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

References