← Back

CVE-2005-0590

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.

Affected (44)

3 products
Firefox
Mozilla
Thunderbird
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Version 0.10.1
Version 0.10
Version 0.8
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9
Version 0.9 rc
Version 1.0
Mozilla
Version 1.3
Version 1.4.1
Version 1.4
Version 1.4 alpha
Version 1.5.1
Version 1.5
Version 1.5 alpha
Version 1.5 rc1
Version 1.5 rc2
Version 1.6
Version 1.6 alpha
Version 1.6 beta
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.5
Version 1.7
Version 1.7 alpha
Version 1.7 beta
Version 1.7 rc1
Version 1.7 rc2
Version 1.7 rc3
Mozilla
Version 0.1
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7.1
Version 0.7.2
Version 0.7.3
Version 0.7
Version 0.8
Version 0.9
Version 1.0

References (22)

Source: secalert@redhat.com
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.