CVE-2005-0590Mozilla Firefox vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
1.8%
top 17.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 1

Description

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/firefox8 versions+7
NVDmozilla/thunderbird13 versions+12
NVDmozilla/mozilla11 versions+10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mq4v-fvj7-qhmj: The installation confirmation dialog in Firefox before 12022-05-01
CVEList
CVE-2005-0590: The installation confirmation dialog in Firefox before 12005-02-28

📋Vendor Advisories

2
Ubuntu
Ubuntu 4.10 update for Firefox vulnerabilities2005-07-28
Red Hat
security flaw2005-02-24

💬Community

1
Bugzilla
CVE-2005-0590 security flaw2018-08-16