CVE

Id
9334  
CVE No.
CVE-2004-0906  
Status
Candidate  
Description
The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary files or execute arbitrary code.  
Phase
Assigned (20040923)  
Votes
None (candidate not yet proposed)  
Comments