CVE-2007-0009
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 50%
exploitation probability
50%top 1% of all CVEs
observed exploitation
nono source reports it
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
Affected products
n/a · n/aReferences
ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.ascftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.aschttp://fedoranews.org/cms/node/2709http://fedoranews.org/cms/node/2711http://fedoranews.org/cms/node/2747http://fedoranews.org/cms/node/2749http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.htmlhttp://rhn.redhat.com/errata/RHSA-2007-0077.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=364323http://secunia.com/advisories/24253