Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."
CVSS Details
- CVSS 3.1 Base Score: 5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-bin. | Oct 30, 2017 | May 2, 2005 |
| Mfsa2005 25 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 1.0.1 | Jul 28, 2005 | May 2, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-jaUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-trUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-nb | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub