CVE-2004-2657
published 2004-12-31CVE-2004-2657: Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a…
PriorityP45low1.7CVSS 2.0
AVLACLAuSCPINAN
EPSS
0.27%
18.9th percentile
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:P/I:N/A:N
vendor_debian1.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2004-2657: firefox - Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of ...
vendor_debian·2004·CVSS 1.7
CVE-2004-2657 [LOW] CVE-2004-2657: firefox - Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of ...
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.
Scope: local
sid: resolved
GHSA
GHSA-qgjc-6844-xqv9: ** DISPUTED ** Mozilla Firefox 1
ghsa_unreviewed·2022-04-29
CVE-2004-2657 [LOW] GHSA-qgjc-6844-xqv9: ** DISPUTED ** Mozilla Firefox 1
** DISPUTED ** Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/archive/1/431021/100/0/threadedhttp://www.securityfocus.com/archive/1/431063/100/0/threadedhttps://bugzilla.mozilla.org/show_bug.cgi?id=234680https://bugzilla.mozilla.org/show_bug.cgi?id=330884http://www.securityfocus.com/archive/1/431021/100/0/threadedhttp://www.securityfocus.com/archive/1/431063/100/0/threadedhttps://bugzilla.mozilla.org/show_bug.cgi?id=234680https://bugzilla.mozilla.org/show_bug.cgi?id=330884
2004-12-31
Published