Description
Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
Published: 2007-09-13
Score: 5.0 Medium
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1532-1 New xulrunner packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1534-1 New iceape packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1534-2 New iceape packages fix regression
Debian DSA Debian DSA DSA-1535-1 New iceweasel packages fix several vulnerabilities
EUVD EUVD EUVD-2007-4860 Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web sites to track user activities across domains by requesting the TLS client certificates from other domains.
Ubuntu USN Ubuntu USN USN-592-1 Firefox vulnerabilities
History

No history.

Subscriptions

Mozilla Firefox Seamonkey
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T15:08:33.876Z

Reserved: 2007-09-13T00:00:00.000Z

Link: CVE-2007-4879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-09-13T18:17:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-4879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses