cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2007-4041,https://securityvulnerability.io/vulnerability/CVE-2007-4041,,"Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.",Microsoft,"Internet Explorer,Firefox",,,0.014700000174343586,false,false,false,false,,false,false,2007-07-27T22:00:00.000Z,0 CVE-2007-3670,https://securityvulnerability.io/vulnerability/CVE-2007-3670,,"Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a ""defense in depth"" fix that will ""prevent IE from sending Firefox malicious data.""",Microsoft,"Internet Explorer,Firefox",,,0.7173200249671936,false,false,false,false,,false,false,2007-07-10T19:00:00.000Z,0 CVE-2006-2057,https://securityvulnerability.io/vulnerability/CVE-2006-2057,,"Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via "" (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE: it is not clear whether this issue is implementation-specific or a problem in the Microsoft API.",Microsoft,"Outlook,Avant Browser,Ie,Firefox",,,0.004170000087469816,false,false,false,false,,false,false,2006-04-26T20:00:00.000Z,0