← Vulnerability feed

Vulnerability record · CVE-2007-0009 · published 26 February 2007

CVE-2007-0009: NSS SSLv2 stack buffer overflow via Client Master Key length

Mozilla · Firefox

Mozilla Network Security Services (NSS) before 3.11.5 contains a stack-based buffer overflow in its SSLv2 support, triggered by invalid "Client Master Key" length values. The flaw affects NSS as shipped in Firefox, Thunderbird, SeaMonkey, and certain Sun Java System server products. Because it is remotely reachable and can lead to code execution, it matters for any system still running these unpatched, long-obsolete versions.

6.8 CVSS 2.0 Medium EPSS 51% · top 1.1% CWE-119 · Memory buffer overflow
6.8CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
132References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a very high EPSS percentile, though the affected software is long end-of-life and no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

Mozilla Network Security Services (NSS) before 3.11.5 contains a stack-based buffer overflow in its SSLv2 support, triggered by invalid "Client Master Key" length values. The flaw affects NSS as shipped in Firefox, Thunderbird, SeaMonkey, and certain Sun Java System server products. Because it is remotely reachable and can lead to code execution, it matters for any system still running these unpatched, long-obsolete versions.

Impact

A remote attacker can execute arbitrary code in the context of the affected process, or at minimum crash it. The CVSS 2.0 vector rates partial confidentiality, integrity, and availability impact.

Attack surface

Reachable over the network (AV:N) through SSLv2 handshake processing, with no authentication required (Au:N); the CVSS vector notes medium access complexity (AC:M). No user interaction is indicated by the record.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.5036 (98.9th percentile), indicating elevated predicted exploitation likelihood. Reference tags are advisory-only (Third Party Advisory, Broken Link) and provide no exploit code or in-the-wild confirmation.

What to do

  • Upgrade NSS to 3.11.5 or later, and update Firefox, Thunderbird, and SeaMonkey to the fixed versions named in the advisory.
  • Apply vendor errata for affected Linux distributions (Red Hat, Debian, Ubuntu, SUSE) and Sun Java System server products.
  • Disable SSLv2 in all TLS/SSL service and client configurations where it is still enabled.
  • Retire or isolate end-of-life products that cannot be patched to a fixed NSS version.
  • Monitor vendor advisories for any backported fixes if legacy versions must remain in service.

Detection

  • Search asset inventories for NSS versions below 3.11.5 and for the affected Firefox, Thunderbird, SeaMonkey, and Sun Java System versions.
  • Inspect TLS/SSL configuration to identify endpoints still negotiating or permitting SSLv2.
  • Monitor network traffic and service logs for malformed SSLv2 Client Master Key handshake messages or repeated handshake failures.
  • Watch for process crashes in NSS-linked services that correlate with inbound TLS connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20070202-01-P.asc Broken Link
ftp://patches.sgi.com/support/free/security/advisories/20070301-01-P.asc Broken Link
http://fedoranews.org/cms/node/2709 Broken Link
http://fedoranews.org/cms/node/2711 Broken Link
http://fedoranews.org/cms/node/2747 Broken Link
http://fedoranews.org/cms/node/2749 Broken Link
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00771742 Broken Link
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=483 Broken Link
http://lists.suse.com/archive/suse-security-announce/2007-Mar/0001.html Broken Link
http://rhn.redhat.com/errata/RHSA-2007-0077.html Third Party Advisory
http://secunia.com/advisories/24253 Third Party Advisory
http://secunia.com/advisories/24277 Third Party Advisory
http://secunia.com/advisories/24287 Third Party Advisory
http://secunia.com/advisories/24290 Third Party Advisory
http://secunia.com/advisories/24293 Third Party Advisory
http://secunia.com/advisories/24333 Third Party Advisory
http://secunia.com/advisories/24342 Third Party Advisory
http://secunia.com/advisories/24343 Third Party Advisory
http://secunia.com/advisories/24384 Third Party Advisory
http://secunia.com/advisories/24389 Third Party Advisory
http://secunia.com/advisories/24395 Third Party Advisory
http://secunia.com/advisories/24406 Third Party Advisory
http://secunia.com/advisories/24410 Third Party Advisory
http://secunia.com/advisories/24455 Third Party Advisory
http://secunia.com/advisories/24456 Third Party Advisory
http://secunia.com/advisories/24457 Third Party Advisory
http://secunia.com/advisories/24522 Third Party Advisory
http://secunia.com/advisories/24562 Third Party Advisory
http://secunia.com/advisories/24650 Third Party Advisory
http://secunia.com/advisories/24703 Third Party Advisory
http://secunia.com/advisories/25588 Third Party Advisory
http://secunia.com/advisories/25597 Third Party Advisory
http://security.gentoo.org/glsa/glsa-200703-18.xml Third Party Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.338131 Mailing ListThird Party Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.363947 Mailing ListThird Party Advisory
http://slackware.com/security/viewer.php?l=slackware-security&y=2007&m=slackware-security.374851 Mailing ListThird Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102945-1 Broken Link
http://www.debian.org/security/2007/dsa-1336 Third Party Advisory
http://www.gentoo.org/security/en/glsa/glsa-200703-22.xml Third Party Advisory

Track CVE-2007-0009 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2019-11708Mozilla Firefox and Thunderbird sandbox escape via Prompt:Open IPC validation flawThe Prompt:Open IPC message between child and parent processes does not sufficiently vet its parameters, letting a compromised child process cause th…KEVEPSS 56%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2007-0009), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.