Vulnerability Name: | CVE-2005-2395 (CCN-22272) | ||||||||
Assigned: | 2005-07-27 | ||||||||
Published: | 2005-07-27 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Sep 14 2005 - 06:41:45 CDT Mozilla / Mozilla Firefox authentication weakness Source: CCN Type: Full-Disclosure Mailing List, Wed Sep 14 2005 - 19:10:00 CDT Mozilla / Mozilla Firefox authentication weakness Source: MITRE Type: CNA CVE-2005-2395 Source: SREASON Type: UNKNOWN 8 Source: CCN Type: Mozilla Firefox Download Web page Firefox - Rediscover the web Source: OSVDB Type: UNKNOWN 19002 Source: CCN Type: OSVDB ID: 19002 Mozilla Multiple Browser Authentication Order Weakness Source: MISC Type: UNKNOWN http://www.securiteam.com/securitynews/5PP0L00GUQ.html Source: BUGTRAQ Type: Exploit 20050719 Mozilla cleartext credentials leak bug report to excuse myself (Re[2]: NTLM HTTP Authentication is insecure by design - a new writeup by Amit Klein) Source: CCN Type: BugTraq Mailing List, Jul 19 2005 08:10PM Mozilla cleartext credentials leak bug report to execute myself Source: CCN Type: BugTraq Mailing List, Sep 14 2005 11:41AM Mozilla / Mozilla Firefox authentication weakness Source: BID Type: UNKNOWN 14325 Source: CCN Type: BID-14325 Multiple Browser Weak Authentication Mechanism Vulnerability Source: MISC Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=281851 Source: XF Type: UNKNOWN mozilla-authentication-weakness(22272) Source: XF Type: UNKNOWN mozilla-authentication-weakness(22272) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |