CVE-2004-2227

Mozilla Firefox <1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.

References (6)

Core 6
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13724
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13144
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200501-03.xml
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/11591
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18016

Scores

EPSS 0.0181
EPSS Percentile 76.2%

Details

Status published
Products (7)
mozilla/firefox 0.8
mozilla/firefox 0.9 (2 CPE variants)
mozilla/firefox 0.9.1
mozilla/firefox 0.9.2
mozilla/firefox 0.9.3
mozilla/firefox 0.10
mozilla/firefox 0.10.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026