VDB
CVE-2005-0234
CVE-2005-0234
PUBLISHED
CVSS 5 MEDIUM
The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
EPSS 1.65% · 75.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.65%
75.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | safari | 1.2.5 |
Timeline
- Feb 7, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
References
- 20050208 International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. mailing-list
- APPLE-SA-2005-03-21 vendor-advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html exploit
- http://www.shmoo.com/idn exploit
- http://www.shmoo.com/idn/homograph.txt advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-0234 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19236 url
- http://www.securityfocus.com/bid/12461 url