Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2004-0906
Description:The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.
Test IDs: 1.3.6.1.4.1.25623.1.0.15432  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2004-0906
BugTraq ID: 11192
http://www.securityfocus.com/bid/11192
CERT/CC vulnerability note: VU#653160
http://www.kb.cert.org/vuls/id/653160
http://security.gentoo.org/glsa/glsa-200409-26.xml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11668
RedHat Security Advisories: RHSA-2005:323
http://www.redhat.com/support/errata/RHSA-2005-323.html
http://secunia.com/advisories/12526/
SuSE Security Announcement: SUSE-SA:2004:036 (Google Search)
http://www.novell.com/linux/security/advisories/2004_36_mozilla.html
XForce ISS Database: mozilla-insecure-file-permissions(17375)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17375




© 1998-2025 E-Soft Inc. All rights reserved.