CVE-2004-2657

Mozilla Firefox <1.5.0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/431063/100/0/threaded
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=330884
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/431021/100/0/threaded
Issue Tracking x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=234680

Scores

EPSS 0.0027
EPSS Percentile 18.7%

Details

Status published
Products (1)
mozilla/firefox 1.5.0.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026