2.6

CVE-2005-0593

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 0.8
Mozilla ≫ Firefox Version 0.9
Mozilla ≫ Firefox Version 0.9 Update rc
Mozilla ≫ Firefox Version 0.9.1
Mozilla ≫ Firefox Version 0.9.2
Mozilla ≫ Firefox Version 0.9.3
Mozilla ≫ Firefox Version 0.10
Mozilla ≫ Firefox Version 0.10.1
Mozilla ≫ Firefox Version 1.0
Mozilla ≫ Mozilla Version 1.3
Mozilla ≫ Mozilla Version 1.4
Mozilla ≫ Mozilla Version 1.4 Update alpha
Mozilla ≫ Mozilla Version 1.4.1
Mozilla ≫ Mozilla Version 1.5
Mozilla ≫ Mozilla Version 1.5 Update alpha
Mozilla ≫ Mozilla Version 1.5 Update rc1
Mozilla ≫ Mozilla Version 1.5 Update rc2
Mozilla ≫ Mozilla Version 1.5.1
Mozilla ≫ Mozilla Version 1.6
Mozilla ≫ Mozilla Version 1.6 Update alpha
Mozilla ≫ Mozilla Version 1.6 Update beta
Mozilla ≫ Mozilla Version 1.7
Mozilla ≫ Mozilla Version 1.7 Update alpha
Mozilla ≫ Mozilla Version 1.7 Update beta
Mozilla ≫ Mozilla Version 1.7 Update rc1
Mozilla ≫ Mozilla Version 1.7 Update rc2
Mozilla ≫ Mozilla Version 1.7 Update rc3
Mozilla ≫ Mozilla Version 1.7.1
Mozilla ≫ Mozilla Version 1.7.2
Mozilla ≫ Mozilla Version 1.7.3
Mozilla ≫ Mozilla Version 1.7.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.66% 0.736
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.gentoo.org/security/en/glsa/glsa-200503-10.xml
Patch
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200503-30.xml
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-176.html
http://www.redhat.com/support/errata/RHSA-2005-384.html
http://www.mozilla.org/security/announce/mfsa2005-14.html
http://www.securityfocus.com/bid/12659
https://bugzilla.mozilla.org/show_bug.cgi?id=258048
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=268483
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=276720
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=277564
Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100044
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9533