Unrated severityNVD Advisory· Published Jun 6, 2007· Updated Jun 16, 2026
CVE-2007-3073
CVE-2007-3073
Description
Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <=2.0.0.4
- (no CPE)range: <=2.0.0.4
Patches
Vulnerability mechanics
References
8- ha.ckers.org/blog/20070516/read-firefox-settings-poc/nvd
- larholm.com/2007/05/25/firefox-0day-local-file-reading/nvd
- larholm.com/2007/06/04/unpatched-input-validation-flaw-in-firefox-2004/nvd
- osvdb.org/35920nvd
- secunia.com/advisories/25481nvd
- www.securityfocus.com/archive/1/470500/100/0/threadednvd
- bugzilla.mozilla.org/show_bug.cginvd
- bugzilla.mozilla.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.