Unrated severityNVD Advisory· Published Jun 6, 2007· Updated Apr 23, 2026
CVE-2007-3072
CVE-2007-3072
Description
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.
Affected products
4cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:mozilla:firefox:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:2.0.0.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- ha.ckers.org/blog/20070516/read-firefox-settings-poc/nvdExploit
- larholm.com/2007/05/25/firefox-0day-local-file-reading/nvdExploit
- secunia.com/advisories/25481nvdVendor Advisory
- ha.ckers.org/blog/20070516/read-firefox-settings-poc/nvd
- larholm.com/2007/06/04/unpatched-input-validation-flaw-in-firefox-2004/nvd
- osvdb.org/35922nvd
- www.securityfocus.com/archive/1/470500/100/0/threadednvd
- bugzilla.mozilla.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.