VulnerabilityModified
CVE-2005-0587
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
MEDIUM 6.5EPSS 1.42%
Does this matter?
Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.
Description
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- mozilla/firefox · mozilla/mozilla
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/19823Broken Link
- http://www.mozilla.org/security/announce/mfsa2005-21.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2006_04_25.htmlBroken Link
- http://www.securityfocus.com/bid/12659Broken Link, Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100037Broken Link
- http://secunia.com/advisories/19823Broken Link
- http://www.mozilla.org/security/announce/mfsa2005-21.htmlVendor Advisory
- http://www.novell.com/linux/security/advisories/2006_04_25.htmlBroken Link
- http://www.securityfocus.com/bid/12659Broken Link, Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100037Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.