Vulnerability Name: | CVE-2007-3144 (CCN-34983) | ||||||||
Assigned: | 2007-06-06 | ||||||||
Published: | 2007-06-06 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attack using HTTP Basic Authentication. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 4.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:UR)
1.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3142 Source: MITRE Type: CNA CVE-2007-3143 Source: MITRE Type: CNA CVE-2007-3144 Source: MITRE Type: CNA CVE-2007-3145 Source: CCN Type: SourceForge.net Galeon Source: OSVDB Type: UNKNOWN 43466 Source: MISC Type: UNKNOWN http://testing.bitsploit.de/test.html Source: CCN Type: The Hacker Webzine Opera HTTP Auth Phishing. Source: MISC Type: Exploit http://www.0x000000.com/?i=334 Source: CCN Type: GLSA-200708-17 Opera: Multiple vulnerabilities Source: CCN Type: Konqueror Web site Konqueror - Web Browser, File Manager - and more! Source: CCN Type: Mozilla Firefox Web site Firefox - Rediscover the Web Source: CCN Type: Opera Web site Download Opera Web Browser Source: CCN Type: OSVDB ID: 43463 Opera Hostname Basic Authentication Status Bar Truncation Spoofing Source: CCN Type: OSVDB ID: 43465 KDE Konqueror Hostname Basic Authentication Status Bar Truncation Spoofing Source: CCN Type: OSVDB ID: 43466 Mozilla Hostname Basic Authentication Status Bar Truncation Spoofing Source: CCN Type: OSVDB ID: 43467 Galeon Hostname Basic Authentication Status Bar Truncation Spoofing Source: BID Type: Exploit 24352 Source: CCN Type: BID-24352 Opera Web Browser Basic Authentication Server Domain Spoofing Vulnerability Source: XF Type: UNKNOWN multiple-basic-authentication-spoofing(34983) Source: XF Type: UNKNOWN multiple-basic-authentication-spoofing(34983) Source: SUSE Type: SUSE-SR:2007:015 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |