CVE-2004-2225: Medium severity Mozilla Firefox vulnerability
Published Dec 31, 2004
·Updated
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
Affected Software
8 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=preview_release
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2225?
CVE-2004-2225 is recognized as a medium severity vulnerability due to the risk of arbitrary file deletion.
2
How do I fix CVE-2004-2225?
To fix CVE-2004-2225, upgrade to Mozilla Firefox version 0.10.1 or later.
3
What versions of Mozilla Firefox are affected by CVE-2004-2225?
CVE-2004-2225 affects Mozilla Firefox versions 0.8, 0.9, and 0.10.
4
What type of attack does CVE-2004-2225 enable?
CVE-2004-2225 enables remote attackers to delete arbitrary files from the user's download directory.
5
Is CVE-2004-2225 still a concern for current Firefox versions?
CVE-2004-2225 is not a concern for current versions of Firefox as it has been patched in later releases.