CVE-2007-4042

Netscape Navigator 9 - Command Injection

Title source: llm
STIX 2.1

Description

Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/46832

Scores

EPSS 0.1032
EPSS Percentile 95.3%

Details

Status published
Products (2)
microsoft/internet_explorer 7
netscape/navigator 9.0
Published Jul 27, 2007
Tracked Since Feb 18, 2026