CVE-2004-0760 : Detail

CVE-2004-0760

1.85%V3
Network
2004-08-03
02h00 +00:00
2017-10-09
22h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.

CVE Informations

Metrics

Metrics Score Severity CVSS Vector Source
V2 6.4 AV:N/AC:L/Au:N/C:P/I:P/A:N nvd@nist.gov

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 24276

Publication date : 2004-07-12 22h00 +00:00
Author : Mind Warper
EDB Verified : Yes

source: https://www.securityfocus.com/bid/10709/info Mozilla Browser is reported prone to multiple vulnerabilities that could eventually allow for code execution on the local computer. These vulnerabilities do not represent a significant threat on their own, however, code execution in the context of the user is possible if the two issues are combined. By combining these issues, an attacker can eventually execute arbitrary HTML or script code in the local zone. The attacker would likely exploit these issues by crafting a malicious Web site containing HTML and script code and entice a user to visit the site. If a user visits the site, the malicious page will be cached in a known directory with a known file name. The attacker may then craft a link to this cached local file and entice a user to follow this link. Due to a flaw in Mozilla that allows cached files to be opened in the local zone as HTML documents the attack may lead to arbitrary code execution in the local zone. It should be noted that this issue is reported to exist in all versions of Mozilla and Firefox browsers, however, Symantec was not able to reproduce this on Firefox 0.9.2. Furthermore, the directory names may vary with different platforms. Update: New reports have stated that the Mozilla Browser is not vulnerable to the first issue as it uses random names for cache directories. This issue does however affect Firefox. It is also reported that an attacker does not have to use a file extension for the second vulnerability as long as a NULL byte is placed after the file name. Arbitrary extensions may be applied as well. file://C:\\Documents and Settings\\Administrator\\Application Data\\Mozilla\\Firefox\\Profiles\\default.nop\\Cache\\_CACHE_002_%00.html

Products Mentioned

Configuraton 0

Mozilla>>Mozilla >> Version *

References

http://www.redhat.com/support/errata/RHSA-2004-421.html
Tags : vendor-advisory, x_refsource_REDHAT
http://marc.info/?l=bugtraq&m=109900315219363&w=2
Tags : vendor-advisory, x_refsource_FEDORA
http://www.securityfocus.com/bid/15495
Tags : vdb-entry, x_refsource_BID