CVE-2007-5960 describes a vulnerability in Mozilla Firefox before version 2.0.0.10 and SeaMonkey before 1.1.7, where the browser incorrectly sets the Referer header. This flaw allows remote attackers to spoof HTTP Referer headers, potentially bypassing Cross-Site Request Forgery (CSRF) protection mechanisms. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and resulting in partial integrity impact. Its EPSS and FAUCET scores suggest a very low likelihood of exploitation and overall risk. There is no evidence of active exploitation, nor is there any known public exploit code available through platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:* | ||
0.9CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:* | ||
0.9.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:* | ||
0.9.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:* | ||
0.9.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.