Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-3670

37
FAUCET Score

CVE-2007-3670 describes an argument injection vulnerability affecting Microsoft Internet Explorer when Firefox is installed and certain URIs are registered. This flaw allows remote attackers to conduct cross-browser scripting and execute arbitrary commands by injecting shell metacharacters into FirefoxURL or FirefoxHTML URIs, which are then used in the command line invoking firefox.exe. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, leading to partial integrity impact. While there is no evidence of active exploitation, an exploit is available on ExploitDB, and the vulnerability has a high EPSS score, suggesting a higher likelihood of exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
6CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:6:*:*:*:*:*:*:*
6CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:7.0:beta1:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:microsoft:internet_explorer:7.0:beta2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
29.35%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-30285 · Jul 10, 2007
This CVE's current EPSS score of 0.2935 is in the 98th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

ftp.slackware.com / pub/slackware/slackware-12.0/ChangeLog.txt
archives.neohapsis.com / archives/fulldisclosure/2007-07/0160.html
blog.mozilla.com / security/2007/07/10/security-issue-in-url-protocol-handling-on-windows
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
labs.idefense.com / intelligence/vulnerabilities/display.php
larholm.com / 2007/07/10/internet-explorer-0day-exploit
msinfluentials.com / blogs/jesper/archive/2007/07/10/blocking-the-firefox-gt-ie-0-day.aspx
osvdb.org / 38017
secunia.com / advisories/25984
Vendor Advisory
secunia.com / advisories/26096
Vendor Advisory
secunia.com / advisories/26149
Vendor Advisory
secunia.com / advisories/26204
Vendor Advisory
secunia.com / advisories/26216
Vendor Advisory
secunia.com / advisories/26258
Vendor Advisory
secunia.com / advisories/26271
Vendor Advisory
secunia.com / advisories/26572
Vendor Advisory
secunia.com / advisories/28179
secunia.com / advisories/28363
exchange.xforce.ibmcloud.com / vulnerabilities/35346
support.novell.com / techcenter/psdb/07d098f99c9fe6956523beae37f32fda.html
kb.cert.org / vuls/id/358017
US Government Resource
mandriva.com / security/advisories
mozilla.org / security/announce/2007/mfsa2007-23.html
mozilla.org / security/announce/2007/mfsa2007-40.html
novell.com / linux/security/advisories/2007_49_mozilla.html
securityfocus.com / archive/1/473276/100/0/threaded
securityfocus.com / bid/24837
securitytracker.com / id
securitytracker.com / id
theregister.co.uk / 2007/07/11/ie_firefox_vuln
ubuntu.com / usn/usn-503-1
us-cert.gov / cas/techalerts/TA07-199A.html
US Government Resource
virusbtn.com / news/virus_news/2007/07_11.xml
vupen.com / english/advisories/2007/2473
vupen.com / english/advisories/2007/2565
vupen.com / english/advisories/2007/4272
vupen.com / english/advisories/2008/0082
xs-sniper.com / sniperscope/IE-Pwns-Firefox.html