CVE-2004-2657
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list…
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.
- CVSS 2.0
- 1.7 LOWAV:L/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/431021/100/0/threaded
- http://www.securityfocus.com/archive/1/431063/100/0/threaded
- https://bugzilla.mozilla.org/show_bug.cgi?id=234680
- https://bugzilla.mozilla.org/show_bug.cgi?id=330884
- http://www.securityfocus.com/archive/1/431021/100/0/threaded
- http://www.securityfocus.com/archive/1/431063/100/0/threaded
- https://bugzilla.mozilla.org/show_bug.cgi?id=234680
- https://bugzilla.mozilla.org/show_bug.cgi?id=330884
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.