VulnerabilityModified
CVE-2007-0802
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist…
MEDIUM 6.4EPSS 2.13%
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- mozilla/firefox · opera/opera browser
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0516.htmlBroken Link
- http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.phpBroken Link, Exploit, Vendor Advisory
- http://osvdb.org/33705Broken Link
- http://www.securityfocus.com/archive/1/459265/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=367538Issue Tracking, Third Party Advisory
- http://archives.neohapsis.com/archives/fulldisclosure/2007-04/0516.htmlBroken Link
- http://kaneda.bohater.net/security/20070111-firefox_2.0.0.1_bypass_phishing_protection.phpBroken Link, Exploit, Vendor Advisory
- http://osvdb.org/33705Broken Link
- http://www.securityfocus.com/archive/1/459265/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=367538Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.