Vulnerability Database

290,020

Total vulnerabilities in the database

CVE-2007-5337

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the target server, in which the web page contains URIs with (1) smb: or (2) sftp: schemes that access other files from the server.

  • Published: Oct 21, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-5337
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:P/I:N/A:N

CWEs:

Software From Fixed in
gnome / gnome-vfs - -
mozilla / firefox - 2.0.0.7.x
mozilla / seamonkey - 1.1.4.x