CVE-2004-2227Information Loss or Omission in Mozilla Firefox

Severity
5.0MEDIUMNVD
EPSS
0.9%
top 24.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox7 versions+6

Patches

🔴Vulnerability Details

1
GHSA
GHSA-655m-g765-53v3: Mozilla Firefox before 12022-04-29

📐Framework References

1
CWE
Information Loss or Omission