SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-0802

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist…

MEDIUM 6.4EPSS 2.13%

Does this matter?

Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.13% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
mozilla/firefox · opera/opera browser
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.