Vulnerability Description
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 0.8 |
References
- http://secunia.com/advisories/12708PatchVendor Advisory
- http://securitytracker.com/id?1011501Patch
- http://www.mozilla.org/projects/security/older-vulnerabilities.html#firefox0.10.
- http://www.osvdb.org/10478Patch
- http://www.securityfocus.com/bid/11311Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=259708PatchVendor Advisory
- http://secunia.com/advisories/12708PatchVendor Advisory
- http://securitytracker.com/id?1011501Patch
- http://www.mozilla.org/projects/security/older-vulnerabilities.html#firefox0.10.
- http://www.osvdb.org/10478Patch
- http://www.securityfocus.com/bid/11311Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=259708PatchVendor Advisory
FAQ
What is CVE-2004-2225?
CVE-2004-2225 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
How severe is CVE-2004-2225?
CVE-2004-2225 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2225?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.