Vulnerability Name: | CVE-2004-2227 (CCN-18016) | ||||||||
Assigned: | 2004-11-10 | ||||||||
Published: | 2004-11-10 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-2227 Source: CCN Type: SA13144 Mozilla Firefox Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 13144 Source: SECUNIA Type: Patch, Vendor Advisory 13724 Source: GENTOO Type: Patch, Vendor Advisory GLSA-200501-03 Source: CCN Type: GLSA-200501-03 Mozilla, Firefox, Thunderbird: Various vulnerabilities Source: CCN Type: Mozilla Web site Firefox - Rediscover the web Source: OSVDB Type: Patch 11591 Source: CCN Type: OSVDB ID: 11591 Mozilla Firefox File Download Truncation Extension Spoofing Source: CCN Type: BID-11643 Mozilla Firefox Download Dialogue Box File Name Spoofing Vulnerability Source: CCN Type: Mozilla Bugzilla Bug 234416 can spoof filename in "what should firefox do with this file" dialog Source: MISC Type: Patch https://bugzilla.mozilla.org/show_bug.cgi?id=234416 Source: XF Type: UNKNOWN mozilla-firefox-ext-spoof(18016) Source: XF Type: UNKNOWN mozilla-firefox-ext-spoof(18016) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |