CVE-2004-0648: Critical severity Mozilla Firefox vulnerability
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0648?
CVE-2004-0648 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary programs.
How do I fix CVE-2004-0648?
To fix CVE-2004-0648, users should upgrade to Mozilla Firefox version 0.9.2 or later, Mozilla Suite version 1.7.1 or later, or Thunderbird version 0.7.2 or later.
Which versions are affected by CVE-2004-0648?
CVE-2004-0648 affects Mozilla Suite versions before 1.7.1, Firefox versions before 0.9.2, and Thunderbird versions before 0.7.2.
What type of attack does CVE-2004-0648 facilitate?
CVE-2004-0648 facilitates an attack that allows the execution of arbitrary programs via a URI using the shell: protocol.
Is there a workaround for CVE-2004-0648 if I cannot upgrade?
A possible workaround for CVE-2004-0648 includes disabling the shell: protocol to prevent execution of remote commands.