5
CVE-2005-0590
- EPSS 1.67%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:11:24
- Erkennungen
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version 0.1
Mozilla ≫ Thunderbird Version 0.2
Mozilla ≫ Thunderbird Version 0.3
Mozilla ≫ Thunderbird Version 0.4
Mozilla ≫ Thunderbird Version 0.5
Mozilla ≫ Thunderbird Version 0.6
Mozilla ≫ Thunderbird Version 0.7
Mozilla ≫ Thunderbird Version 0.7.1
Mozilla ≫ Thunderbird Version 0.7.2
Mozilla ≫ Thunderbird Version 0.7.3
Mozilla ≫ Thunderbird Version 0.8
Mozilla ≫ Thunderbird Version 0.9
Mozilla ≫ Thunderbird Version 1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.67% | 0.738 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/19823
http://www.novell.com/linux/security/advisories/2006_04_25.html
http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
http://www.redhat.com/support/errata/RHSA-2005-176.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.securityfocus.com/bid/12659
http://www.mozilla.org/security/announce/mfsa2005-17.html
https://bugzilla.mozilla.org/show_bug.cgi?id=268059
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100041
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10010