Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2007 22 | — | Upgrade to Mozilla Firefox version 2.0.0.5 | Jun 14, 2012 | Jun 20, 2007 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.3 | Feb 3, 2012 | Jun 20, 2007 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-common | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jun 20, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub