CVE-2007-1362 is a denial-of-service vulnerability affecting Mozilla Firefox versions 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey versions 1.0.9 and 1.1.2. It allows remote attackers to cause memory consumption or misinterpretation of cookie data through excessively large or malformed cookie path parameters. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and partial availability impact, with no confidentiality or integrity impact. While there is an ExploitDB entry for a denial-of-service proof-of-concept, there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:* | ||
1.5.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:1.5.0.2:*:*:*:*:*:*:* | ||
1.5.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:1.5.0.3:*:*:*:*:*:*:* | ||
1.5.0.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:1.5.0.4:*:*:*:*:*:*:* | ||
1.5.0.5CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:1.5.0.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.