Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2005-0230

Опубликовано: 02 мая 2005
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 5.1

Описание

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

РелизСтатусПримечание
dapper

not-affected

devel

DNE

edgy

not-affected

feisty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

EPSS

Процентиль: 84%
0.0221
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

nvd
около 20 лет назад

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

debian
около 20 лет назад

Firefox 1.0 does not prevent the user from dragging an executable file ...

github
около 3 лет назад

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

EPSS

Процентиль: 84%
0.0221
Низкий

5.1 Medium

CVSS2