CyberSec.Space Logo
Back to CVE Browser

CVE-2007-4841

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.1870%
EPSS Percentile12.26th
PublishedSep 12, 2007
Last ModifiedApr 23, 2026

Vulnerability Description

Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file type handling on Windows XP with Internet Explorer 7 installed, a variant of CVE-2007-3845.

Affected Platforms (CPE)

πŸ“¦
Mozilla

Firefox

<= 2.0.0.8
πŸ“¦
Mozilla

Seamonkey

<= 1.1.5
πŸ“¦
Mozilla

Thunderbird

<= 2.0.0.8

References & Advisories

Related Vulnerabilities