Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.9%