Vulnerability record · CVE-2007-0009 · published 26 February 2007
CVE-2007-0009: NSS SSLv2 stack buffer overflow via Client Master Key length
Mozilla · Firefox
Mozilla Network Security Services (NSS) before 3.11.5 contains a stack-based buffer overflow in its SSLv2 support, triggered by invalid "Client Master Key" length values. The flaw affects NSS as shipped in Firefox, Thunderbird, SeaMonkey, and certain Sun Java System server products. Because it is remotely reachable and can lead to code execution, it matters for any system still running these unpatched, long-obsolete versions.
Description
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a very high EPSS percentile, though the affected software is long end-of-life and no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Mozilla Network Security Services (NSS) before 3.11.5 contains a stack-based buffer overflow in its SSLv2 support, triggered by invalid "Client Master Key" length values. The flaw affects NSS as shipped in Firefox, Thunderbird, SeaMonkey, and certain Sun Java System server products. Because it is remotely reachable and can lead to code execution, it matters for any system still running these unpatched, long-obsolete versions.
Impact
A remote attacker can execute arbitrary code in the context of the affected process, or at minimum crash it. The CVSS 2.0 vector rates partial confidentiality, integrity, and availability impact.
Attack surface
Reachable over the network (AV:N) through SSLv2 handshake processing, with no authentication required (Au:N); the CVSS vector notes medium access complexity (AC:M). No user interaction is indicated by the record.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.5036 (98.9th percentile), indicating elevated predicted exploitation likelihood. Reference tags are advisory-only (Third Party Advisory, Broken Link) and provide no exploit code or in-the-wild confirmation.
What to do
- Upgrade NSS to 3.11.5 or later, and update Firefox, Thunderbird, and SeaMonkey to the fixed versions named in the advisory.
- Apply vendor errata for affected Linux distributions (Red Hat, Debian, Ubuntu, SUSE) and Sun Java System server products.
- Disable SSLv2 in all TLS/SSL service and client configurations where it is still enabled.
- Retire or isolate end-of-life products that cannot be patched to a fixed NSS version.
- Monitor vendor advisories for any backported fixes if legacy versions must remain in service.
Detection
- Search asset inventories for NSS versions below 3.11.5 and for the affected Firefox, Thunderbird, SeaMonkey, and Sun Java System versions.
- Inspect TLS/SSL configuration to identify endpoints still negotiating or permitting SSLv2.
- Monitor network traffic and service logs for malformed SSLv2 Client Master Key handshake messages or repeated handshake failures.
- Watch for process crashes in NSS-linked services that correlate with inbound TLS connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0009 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0009), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.