Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Firefox | Mozilla | 0.8 | 0.8 |
Firefox | Mozilla | 0.9 | 0.9 |
Firefox | Mozilla | 0.9 | 0.9 |
Firefox | Mozilla | 0.9.1 | 0.9.1 |
Firefox | Mozilla | 0.9.2 | 0.9.2 |
Firefox | Mozilla | 0.9.3 | 0.9.3 |
Firefox | Mozilla | 0.10 | 0.10 |
Firefox | Mozilla | preview_release | preview_release |