{"api_version":"1","generated_at":"2026-07-23T06:03:48+00:00","cve":"CVE-2004-2657","urls":{"html":"https://cve.report/CVE-2004-2657","api":"https://cve.report/api/cve/CVE-2004-2657.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2657","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2657"},"summary":{"title":"CVE-2004-2657","description":"Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites.  NOTE: The vendor has disputed this issue, stating that \"The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/431063/100/0/threaded","name":"http://www.securityfocus.com/archive/1/431063/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/431021/100/0/threaded","name":"http://www.securityfocus.com/archive/1/431021/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=330884","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=330884","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 330884 – When different users on one system choose to save or not save passwords for sites, any other user can see sites they not only saved passwords for but can also see what other users have been saving/never saving passwords for.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=234680","name":"https://bugzilla.mozilla.org/show_bug.cgi?id=234680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"234680 – Uninstall should give the option to remove profile data","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2657","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2657","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2657","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mozilla","cpe5":"firefox","cpe6":"1.5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:36:25.142Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20060415 Re: Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/431063/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=330884"},{"name":"20060413 Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/431021/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=234680"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-02-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites.  NOTE: The vendor has disputed this issue, stating that \"The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20060415 Re: Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/431063/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=330884"},{"name":"20060413 Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/431021/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=234680"}],"tags":["disputed"],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2657","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"** DISPUTED **  Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites.  NOTE: The vendor has disputed this issue, stating that \"The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20060415 Re: Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/431063/100/0/threaded"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=330884","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=330884"},{"name":"20060413 Firefox 1.5.0.1 Password Manager Arbtirary User Browsing History Disclosure","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/431021/100/0/threaded"},{"name":"https://bugzilla.mozilla.org/show_bug.cgi?id=234680","refsource":"MISC","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=234680"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2657","datePublished":"2006-04-20T22:00:00.000Z","dateReserved":"2006-04-20T00:00:00.000Z","dateUpdated":"2024-08-08T01:36:25.142Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mozilla:firefox:1.5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"7D6BF5B1-86D1-47FE-9D9C-735718F94874"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2657","Ordinal":"1","Title":"CVE-2004-2657","CVE":"CVE-2004-2657","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2657","Ordinal":"1","NoteData":"Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites.  NOTE: The vendor has disputed this issue, stating that \"The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.","Type":"Description","Title":"CVE-2004-2657"},{"CveYear":"2004","CveId":"2657","Ordinal":"2","NoteData":"2006-04-20","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2657","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}