SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0367

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing…

MEDIUM 5.0EPSS 1.81%

Does this matter?

Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
1.81% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
mozilla/firefox
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.