Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option. NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.
CVSS Details
- CVSS 3.1 Base Score: 3.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-mozillaUpgrade thunderbirdUpgrade linux-seamonkeyUpgrade firefoxUpgrade mozilla-thunderbirdUpgrade linux-firefoxUpgrade mozillaUpgrade linux-mozilla-devel | Dec 10, 2025 | Apr 16, 2006 |
| Gentoo Linux | — | Upgrade www-client/mozilla-bin.Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox. | Oct 30, 2017 | Apr 14, 2006 |
| Mfsa2006 13 | — | Upgrade to Mozilla Firefox version 1.0.8Upgrade to Mozilla Firefox version 1.5 | Nov 21, 2013 | Apr 14, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.0 | Nov 21, 2013 | Apr 14, 2006 |
| Suse | — | Upgrade mozilla-mailUpgrade mozilla-deatUpgrade mozilla-venkmanUpgrade mozilla-jaUpgrade mozilla-dom-inspectorUpgrade mozilla-develUpgrade mozilla-csUpgrade mozilla-ircUpgrade mozilla-koUpgrade mozillaUpgrade mozilla-calendarUpgrade mozilla-hu | Feb 17, 2015 | Apr 14, 2006 |
| Ubuntu | — | Upgrade mozilla-firefoxUpgrade mozilla-psm | Nov 8, 2024 | Apr 14, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub