VDB
CVE-2005-0590
CVE-2005-0590
PUBLISHED
Reported by redhat · Published February 28, 2005
The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Feb 28, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 12659 vdb-entryx_refsource_BID
- 19823 third-party-advisoryx_refsource_SECUNIA
- x_refsource_CONFIRM
- oval:org.mitre.oval:def:100041 vdb-entrysignaturex_refsource_OVAL
- x_refsource_CONFIRM
- oval:org.mitre.oval:def:10010 vdb-entrysignaturex_refsource_OVAL
- RHSA-2005:176 vendor-advisoryx_refsource_REDHAT
- RHSA-2005:384 vendor-advisoryx_refsource_REDHAT
- GLSA-200503-30 vendor-advisoryx_refsource_GENTOO
- GLSA-200503-10 vendor-advisoryx_refsource_GENTOO
- SUSE-SA:2006:022 vendor-advisoryx_refsource_SUSE