Unrated severityNVD Advisory· Published Apr 26, 2007· Updated Apr 23, 2026
CVE-2007-2292
CVE-2007-2292
Description
CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.
Affected products
3- cpe:2.3:a:microsoft:internet_explorer:7.0.5730.11:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
52- secunia.com/advisories/27276nvdVendor Advisory
- secunia.com/advisories/27298nvdVendor Advisory
- secunia.com/advisories/27311nvdVendor Advisory
- secunia.com/advisories/27315nvdVendor Advisory
- secunia.com/advisories/27325nvdVendor Advisory
- secunia.com/advisories/27327nvdVendor Advisory
- secunia.com/advisories/27335nvdVendor Advisory
- secunia.com/advisories/27336nvdVendor Advisory
- secunia.com/advisories/27356nvdVendor Advisory
- secunia.com/advisories/27383nvdVendor Advisory
- secunia.com/advisories/27387nvdVendor Advisory
- secunia.com/advisories/27403nvdVendor Advisory
- secunia.com/advisories/27414nvdVendor Advisory
- secunia.com/advisories/27425nvdVendor Advisory
- secunia.com/advisories/27480nvdVendor Advisory
- secunia.com/advisories/27665nvdVendor Advisory
- h20000.www2.hp.com/bizsupport/TechSupport/Document.jspnvd
- secunia.com/advisories/27360nvd
- secunia.com/advisories/27680nvd
- secunia.com/advisories/28398nvd
- securityreason.com/securityalert/2654nvd
- sunsolve.sun.com/search/document.donvd
- support.novell.com/techcenter/psdb/60eb95b75c76f9fbfcc9a89f99cd8f79.htmlnvd
- www.debian.org/security/2007/dsa-1392nvd
- www.debian.org/security/2007/dsa-1396nvd
- www.debian.org/security/2007/dsa-1401nvd
- www.gentoo.org/security/en/glsa/glsa-200711-14.xmlnvd
- www.mandriva.com/en/security/advisoriesnvd
- www.mozilla.org/security/announce/2007/mfsa2007-31.htmlnvd
- www.novell.com/linux/security/advisories/2007_57_mozilla.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0979.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0980.htmlnvd
- www.redhat.com/support/errata/RHSA-2007-0981.htmlnvd
- www.securityfocus.com/archive/1/466906/100/0/threadednvd
- www.securityfocus.com/archive/1/482876/100/200/threadednvd
- www.securityfocus.com/archive/1/482925/100/0/threadednvd
- www.securityfocus.com/archive/1/482932/100/200/threadednvd
- www.securityfocus.com/bid/23668nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/usn-536-1nvd
- www.vupen.com/english/advisories/2007/3544nvd
- www.vupen.com/english/advisories/2007/3587nvd
- www.vupen.com/english/advisories/2008/0083nvd
- www.wisec.it/vulns.phpnvd
- bugzilla.mozilla.org/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/33981nvd
- issues.rpath.com/browse/RPL-1858nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10195nvd
- usn.ubuntu.com/535-1/nvd
- www.redhat.com/archives/fedora-package-announce/2007-November/msg00498.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2007-October/msg00285.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2007-October/msg00355.htmlnvd
News mentions
0No linked articles in our index yet.