Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-mozilla-develUpgrade de-linux-mozillafirebirdUpgrade linux-mozillafirebirdUpgrade linux-mozillaUpgrade linux-netscapeUpgrade el-linux-mozillafirebirdUpgrade ja-linux-netscapeUpgrade firefoxUpgrade ru-linux-mozillafirebirdUpgrade mozillaUpgrade mozilla-firebirdUpgrade ja-netscape7Upgrade phoenixUpgrade zhCN-linux-mozillafirebirdUpgrade fr-linux-netscapeUpgrade ja-linux-mozillafirebird-gtk1Upgrade mozilla+ipv6Upgrade mozilla-gtk1Upgrade de-linux-netscapeUpgrade zhTW-linux-mozillafirebirdUpgrade mozilla-embeddedUpgrade mozilla-gtk2Upgrade ja-mozillafirebird-gtk2Upgrade netscape7Upgrade linux-firefoxUpgrade de-netscape7Upgrade mozilla-thunderbirdUpgrade fr-netscape7Upgrade mozilla-gtkUpgrade linux-phoenixUpgrade pt_BR-netscape7 | Dec 10, 2025 | Sep 22, 2005 |
| Ubuntu | — | Upgrade mozilla-browserUpgrade mozilla-mailnews | Nov 8, 2024 | Sep 20, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub