Mozilla Firefox prior to 0.10.1 allows remote malicious users to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla firefox 0.9.3 |
||
mozilla firefox preview_release |
||
mozilla firefox 0.10 |
||
mozilla firefox 0.8 |
||
mozilla firefox 0.9 |
||
mozilla firefox 0.9.1 |
||
mozilla firefox 0.9.2 |