Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
References
Link | Resource |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=234416 | Patch |
http://security.gentoo.org/glsa/glsa-200501-03.xml | Patch Vendor Advisory |
http://www.osvdb.org/11591 | Patch |
http://secunia.com/advisories/13144 | Patch Vendor Advisory |
http://secunia.com/advisories/13724 | Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18016 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-12-30 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-2227
Mitre link : CVE-2004-2227
JSON object : View
CWE
Products Affected
mozilla
- firefox