VulnerabilityModified
CVE-2005-0591
Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
LOW 2.6EPSS 2.02%
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox
- Source
- secalert@redhat.com
References
- http://marc.info/?l=bugtraq&m=110547286002188&w=2
- http://secunia.com/advisories/13786
- http://www.gentoo.org/security/en/glsa/glsa-200503-10.xmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200503-30.xmlPatch, Vendor Advisory
- http://www.mikx.de/firespoofing/Exploit
- http://www.mikx.de/index.php?p=7Vendor Advisory
- http://www.mozilla.org/security/announce/mfsa2005-16.html
- http://www.redhat.com/support/errata/RHSA-2005-176.html
- http://www.redhat.com/support/errata/RHSA-2005-384.html
- http://www.securityfocus.com/bid/12234
- https://bugzilla.mozilla.org/show_bug.cgi?id=260560Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18864
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100042
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10039
- http://marc.info/?l=bugtraq&m=110547286002188&w=2
- http://secunia.com/advisories/13786
- http://www.gentoo.org/security/en/glsa/glsa-200503-10.xmlPatch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200503-30.xmlPatch, Vendor Advisory
- http://www.mikx.de/firespoofing/Exploit
- http://www.mikx.de/index.php?p=7Vendor Advisory
- http://www.mozilla.org/security/announce/mfsa2005-16.html
- http://www.redhat.com/support/errata/RHSA-2005-176.html
- http://www.redhat.com/support/errata/RHSA-2005-384.html
- http://www.securityfocus.com/bid/12234
- https://bugzilla.mozilla.org/show_bug.cgi?id=260560Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18864
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A100042
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10039
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.