CVE-2004-0779

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:firebirdsql:firebird:0.7:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozilla:1.6:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://bugzilla.mozilla.org/show_bug.cgi?id=226278 - () http://bugzilla.mozilla.org/show_bug.cgi?id=226278 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2004:082 - () http://www.mandriva.com/security/advisories?name=MDKSA-2004:082 -
References () http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7 - () http://www.mozilla.org/projects/security/known-vulnerabilities.html#mozilla1.7 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17018 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17018 -

Information

Published : 2004-08-18 04:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-0779

Mitre link : CVE-2004-0779

CVE.ORG link : CVE-2004-0779


JSON object : View

Products Affected

mozilla

  • mozilla
  • firefox

firebirdsql

  • firebird