Description
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
References (6)
Core 6
Core References
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/13724
Patch x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=234416
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/13144
Patch, Vendor Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200501-03.xml
Patch vdb-entry
x_refsource_osvdb
http://www.osvdb.org/11591
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18016
Scores
EPSS
0.0181
EPSS Percentile
76.2%
Details
Status
published
Products (7)
mozilla/firefox
0.8
mozilla/firefox
0.9 (2 CPE variants)
mozilla/firefox
0.9.1
mozilla/firefox
0.9.2
mozilla/firefox
0.9.3
mozilla/firefox
0.10
mozilla/firefox
0.10.1
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026