AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-4039

CRITICAL · CVSS 9.8 EPSS 2.01%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-07-27 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.

CVE
CVE-2007-4039
Severity
CRITICAL
CVSS
9.8
EPSS
2.01%

Original NVD Description

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.