CVE-2005-2395
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2005
Last modified:
03/04/2025
Description
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://securityreason.com/securityalert/8
- http://www.osvdb.org/19002
- http://www.securiteam.com/securitynews/5PP0L00GUQ.html
- http://www.securityfocus.com/archive/1/405666
- http://www.securityfocus.com/bid/14325
- https://bugzilla.mozilla.org/show_bug.cgi?id=281851
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22272
- http://securityreason.com/securityalert/8
- http://www.osvdb.org/19002
- http://www.securiteam.com/securitynews/5PP0L00GUQ.html
- http://www.securityfocus.com/archive/1/405666
- http://www.securityfocus.com/bid/14325
- https://bugzilla.mozilla.org/show_bug.cgi?id=281851
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22272