CVE-2005-0142 describes a vulnerability in Firefox 0.9 and earlier, Thunderbird 0.6 and earlier, and Mozilla 1.7 before 1.7.5, where temporary files are saved with world-readable permissions. This flaw allows local users to access sensitive web content or attachments, such as PDFs, that are managed by helper applications and belong to other users. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating a local attack vector with low complexity and a potential impact limited to confidentiality. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, with no mentions across social media or news articles, which is typical for a large percentage of older vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:* | ||
1.7CPE matchmatch criteria | cpe:2.3:a:mozilla:mozilla:1.7:*:*:*:*:*:*:* | ||
1.7CPE matchmatch criteria | cpe:2.3:a:mozilla:mozilla:1.7:rc3:*:*:*:*:*:* | ||
1.7.1CPE matchmatch criteria | cpe:2.3:a:mozilla:mozilla:1.7.1:*:*:*:*:*:*:* | ||
1.7.2CPE matchmatch criteria | cpe:2.3:a:mozilla:mozilla:1.7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.