CVE-2007-4841 is a critical vulnerability affecting Mozilla Firefox, Thunderbird, and SeaMonkey versions prior to 2.0.0.8, 2.0.0.8, and 1.1.5 respectively. This flaw allows remote attackers to execute arbitrary commands by exploiting improper handling of malformed URI schemes (mailto, nntp, news, snews) with invalid percent encoding, specifically on Windows XP systems with Internet Explorer 7 installed. With a CVSS score of 9.3, it represents a high-severity risk, enabling complete compromise of confidentiality, integrity, and availability with medium attack complexity and no authentication required. While no active exploitation, Metasploit modules, or ExploitDB entries are publicly available, its high FAUCET Risk Score of 86/100 indicates significant potential danger. Community discussion and media coverage for this vulnerability are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.0.8CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
<= 1.1.5CPE matchmatch criteria | cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* | ||
<= 2.0.0.8CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.