The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in an FTP PASV response.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade web/curl to version 7.74.0-11.4.33.0.1.94.0 on Solaris 11.4 | May 19, 2021 | Mar 21, 2007 |
| Oracle_linux | — | Upgrade firefoxUpgrade devhelpUpgrade yelpUpgrade firefox-develUpgrade devhelp-devel | Oct 16, 2024 | Mar 21, 2007 |
| Suse | — | Upgrade seamonkey-venkmanUpgrade mozilla-mailUpgrade seamonkey-spellcheckerUpgrade seamonkey-mailUpgrade mozilla-calendarUpgrade mozillaUpgrade mozilla-huUpgrade MozillaThunderbirdUpgrade mozilla-csUpgrade mozilla-dom-inspectorUpgrade MozillaFirefoxUpgrade seamonkey-ircUpgrade MozillaThunderbird-translationsUpgrade seamonkeyUpgrade mozilla-venkmanUpgrade mozilla-ircUpgrade mozilla-deatUpgrade mozilla-develUpgrade seamonkey-dom-inspectorUpgrade MozillaFirefox-translationsUpgrade suse-release | Feb 17, 2015 | Mar 21, 2007 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Mar 21, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub