Vulnerability Name: | CVE-2005-2602 (CCN-21754) | ||||||||
Assigned: | 2005-08-09 | ||||||||
Published: | 2005-08-09 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-2602 Source: CCN Type: BugTraq Mailing List, 2005-08-09 13:22:58 Mozilla Firefox up to 1.0.6 and Mozilla Thunderbird up to 1.0 url string obfuscation Source: CCN Type: Mozilla Firefox Download Web page Firefox - Rediscover the web Source: CCN Type: Mozilla Suite Web page Mozilla Suite- The All-in-One Internet Application Suite Source: CCN Type: OSVDB ID: 18691 Mozilla Firefox Long URL Navigation Toolbar Obfuscation Source: MISC Type: UNKNOWN http://www.scip.ch/cgi-bin/smss/showadvf.pl?id=1682 Source: BUGTRAQ Type: Exploit, Vendor Advisory 20050809 Mozilla Firefox up to 1.0.6 and Mozilla Thunderbird up to 1.0 url string obfuscation Source: BID Type: UNKNOWN 14526 Source: CCN Type: BID-14526 Mozilla Firefox And Thunderbird Long URI Obfuscation Weakness Source: XF Type: UNKNOWN mozilla-url-obfuscation(21754) Source: CCN Type: IBM Internet Security Systems X-Force Database IIS can be remotely crashed by excessively long client requests | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |