VulnerabilityModified
CVE-2004-0907
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute…
MEDIUM 4.6EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute arbitrary code.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/mozilla · mozilla/thunderbird
- Source
- cve@mitre.org
References
- http://bugzilla.mozilla.org/show_bug.cgi?id=254303Patch
- http://security.gentoo.org/glsa/glsa-200409-26.xml
- http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17373
- http://bugzilla.mozilla.org/show_bug.cgi?id=254303Patch
- http://security.gentoo.org/glsa/glsa-200409-26.xml
- http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7.3
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17373
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.