4.6
CVSSv2

CVE-2004-0906

Published: 31/12/2004 Updated: 11/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla prior to 1.7.3, and Thunderbird prior to 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla mozilla 0.9.35

mozilla mozilla 0.9.4

mozilla mozilla 0.9.2.1

mozilla mozilla 0.9.3

mozilla mozilla 0.9.7

mozilla mozilla 0.9.8

mozilla mozilla 1.1

mozilla mozilla 1.4

mozilla mozilla 1.4.1

mozilla mozilla 1.6

mozilla mozilla 1.7

mozilla mozilla 1.7.1

mozilla thunderbird 0.1

mozilla thunderbird 0.2

mozilla thunderbird 0.7.2

mozilla thunderbird 0.7.3

mozilla mozilla 0.9.4.1

mozilla mozilla 0.9.48

mozilla mozilla 1.0.2

mozilla mozilla 1.0

mozilla mozilla 1.2

mozilla thunderbird 0.5

mozilla thunderbird 0.6

mozilla mozilla 0.9.9

mozilla mozilla 1.0.1

mozilla mozilla 1.2.1

mozilla mozilla 1.4.2

mozilla mozilla 1.4.4

mozilla mozilla 1.7.2

mozilla thunderbird 0.3

mozilla thunderbird 0.4

mozilla mozilla 0.8

mozilla mozilla 0.9.2

mozilla mozilla 0.9.5

mozilla mozilla 0.9.6

mozilla mozilla 1.3

mozilla mozilla 1.3.1

mozilla mozilla 1.5

mozilla mozilla 1.5.1

mozilla thunderbird 0.7

mozilla thunderbird 0.7.1

Vendor Advisories

Synopsis mozilla security update Type/Severity Security Advisory: Critical Topic Updated mozilla packages that fix various bugs are now availableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Mozilla is an open source Web bro ...