CVE-2004-1449: Low severity mozilla mozilla vulnerability
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1449?
CVE-2004-1449 has a medium severity rating due to its potential to expose sensitive file paths to remote attackers.
How do I fix CVE-2004-1449?
To fix CVE-2004-1449, upgrade to Mozilla versions 1.7 or later, Firefox 0.9 or later, or Thunderbird 0.7 or later.
Who is affected by CVE-2004-1449?
CVE-2004-1449 affects users of Mozilla before version 1.7, Firefox before version 0.9, and Thunderbird before version 0.7.
What is the impact of CVE-2004-1449?
The impact of CVE-2004-1449 is the potential exposure of a user's file path when they are tricked into dragging text into a file upload control.
Is there a workaround for CVE-2004-1449?
There are no known workarounds for CVE-2004-1449; upgrading to the latest software version is the recommended solution.