{ "schema_version": "1.4.0", "id": "GHSA-g79j-r2mj-4w72", "modified": "2025-04-09T03:42:32Z", "published": "2022-05-01T18:10:49Z", "aliases": [ "CVE-2007-3150" ], "details": "Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV=\"refresh\" that targets a www.google.com search for a local .exe file, which is displayed in the \"results stored on your computer\" portion of the search results, and when clicked invokes Google Desktop to execute this file.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-3150" }, { "type": "WEB", "url": "http://ha.ckers.org/blog/20070531/google-desktop-0day" }, { "type": "WEB", "url": "http://ha.ckers.org/google-desktop-0day" }, { "type": "WEB", "url": "http://osvdb.org/40566" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-06-11T19:30:00Z" } }