CVE-2007-3150
Estado: ModificadaAlta (9.3)—
Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file, which is displayed in the "results stored on your computer" portion of the search results, and when clicked invokes Google Desktop to execute this file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.16%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-3150",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-06-11T19:30:00.000",
"references": [
{
"url": "http://ha.ckers.org/blog/20070531/google-desktop-0day/",
"source": "cve@mitre.org"
},
{
"url": "http://ha.ckers.org/google-desktop-0day/",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/40566",
"source": "cve@mitre.org"
},
{
"url": "http://ha.ckers.org/blog/20070531/google-desktop-0day/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://ha.ckers.org/google-desktop-0day/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/40566",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV=\"refresh\" that targets a www.google.com search for a local .exe file, which is displayed in the \"results stored on your computer\" portion of the search results, and when clicked invokes Google Desktop to execute this file."
},
{
"lang": "es",
"value": "Google Desktop permite a atacantes con la intervención del usuario ejecutar programas de su elección a través de un ataque de hombre en el medio (man-in-the-middle) que inyecta JavaScript, un IFRAMe de búsqueda www.google.com, y un META HTTP-EQUIV=\"refresh\" que hace blanco en una búsqueda www.google.com para un fichero local .exe, lo cual se muestra en la parte de \"resultados almacenado sobre tu PC (results stored on your computer)\" del resultado de búsqueda, y cuando al clickar invocamos Google Desktop para ejecutar este fichero."
}
],
"lastModified": "2026-06-16T22:41:10.080",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:google:desktop:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8CAB8A8E-45AD-4E60-AB59-599506B31BD4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}