Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 22.0.x |
| mozilla / firefox | 19.0 | 19.0.x |
| mozilla / firefox | 19.0.1 | 19.0.1.x |
| mozilla / firefox | 19.0.2 | 19.0.2.x |
| mozilla / firefox | 20.0 | 20.0.x |
| mozilla / firefox | 20.0.1 | 20.0.1.x |
| mozilla / firefox | 21.0 | 21.0.x |