Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of the input control that is associated with an event handler.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade mozilla-thunderbirdUpgrade thunderbirdUpgrade mozillaUpgrade linux-mozillaUpgrade firefoxUpgrade linux-mozilla-develUpgrade linux-seamonkey | Dec 10, 2025 | Apr 16, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla-bin.Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Apr 14, 2006 |
| Mfsa2006 23 | — | Upgrade to Mozilla Firefox version 1.0.8Upgrade to Mozilla Firefox version 1.5.0.2 | Nov 21, 2013 | Apr 14, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.1 | Nov 21, 2013 | Apr 14, 2006 |
| Suse | — | Upgrade mozilla-csUpgrade mozilla-mailUpgrade mozilla-jaUpgrade mozilla-ircUpgrade mozilla-deatUpgrade mozilla-venkmanUpgrade mozilla-develUpgrade mozilla-koUpgrade mozillaUpgrade mozilla-huUpgrade mozilla-calendarUpgrade mozilla-dom-inspector | Feb 17, 2015 | Apr 14, 2006 |
| Ubuntu | — | Upgrade mozilla-psmUpgrade mozilla-browserUpgrade firefoxUpgrade mozilla-mailnewsUpgrade mozilla-firefox | Nov 8, 2024 | Apr 14, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub