CVE-2004-0648
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
- Affected products
- Firefox, Mozilla Firefox, Thunderbird
- Mozilla Firefox
- ≤ 0.9.2
- Mozilla
- ≤ 1.7.1
- Mozilla Thunderbird
- ≤ 0.7.2
- Fix
- Available
- CVSS 2.0
- 10.0 HIGH
- EPSS
- 5.3% (92th percentile)
- NVD status
- Modified
- Published
- 2004-07-13
CVE-2004-0648 at NVD
1 known exploit for CVE-2004-0648
Proof-of-concept code and exploit modules indexed by Sploitus