CVE-2005-0142
Last modified
CVE-2005-0142 is a vulnerability of currently unknown severity. Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 0.9 |
| Mozilla | Mozilla | 1.7 |
| Mozilla | Mozilla | 1.7.1 |
| Mozilla | Mozilla | 1.7.2 |
| Mozilla | Mozilla | 1.7.3 |
| Mozilla | Thunderbird | 0.6 |
| Mozilla | Thunderbird | 0.7 |
| Mozilla | Thunderbird | 0.8 |
References
- http://www.mozilla.org/security/announce/mfsa2005-02.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-335.htmlPatch, Vendor Advisory
- http://www.mozilla.org/security/announce/mfsa2005-02.htmlVendor Advisory
- http://www.redhat.com/support/errata/RHSA-2005-335.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0142?
How severe is CVE-2005-0142?
How do I fix CVE-2005-0142?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0136The Linux kernel before 2.6.11 on the Itanium IA64 platform …
- CVE-2005-0137Linux kernel 2.6 on Itanium (ia64) architectures allows loca…
- CVE-2005-0138rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not c…
- CVE-2005-0139Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.…
- CVE-2005-0140Buffer overflow in PeID allows attackers to execute arbitrar…
- CVE-2005-0141Firefox before 1.0 and Mozilla before 1.7.5 allow remote att…
- CVE-2005-0143Firefox before 1.0 and Mozilla before 1.7.5 display the SSL …
- CVE-2005-0144Firefox before 1.0 and Mozilla before 1.7.5 display the secu…
- CVE-2005-0145Firefox before 1.0 does not properly distinguish between use…
- CVE-2005-0146Firefox before 1.0 and Mozilla before 1.7.5 allow remote att…
- CVE-2005-0147Firefox before 1.0 and Mozilla before 1.7.5, when configured…
- CVE-2005-0148Thunderbird before 0.9, when running on Windows systems, use…
Are you affected by CVE-2005-0142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
