Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox URLBar空字节处理远程代码执行漏洞
Vulnerability Description
Mozilla Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Firefox在处理文件URL串时存在输入验证漏洞,攻击者可能利用此漏洞通过诱使用户输入恶意URL到地址栏在用户系统上执行恶意代码。 如果文件名URL包含有空字节(%00)的话,Firefox可能将其解释成为不同的文件类型,这就可能导致一些不安全的操作,如运行程序。攻击者只有本地访问Firefox并在地址栏中输入恶意file:///或resource:///请求后才可以利用这个漏洞,无法通过诱骗用户访问网
CVSS Information
N/A
Vulnerability Type
N/A