Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-0763

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2004-0763
Last Modified 21 Aug 2010 12:21:13
Published 18 Aug 2004 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2004-0763

Summary

Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.

Vulnerable Systems

Application

  • Mozilla Firefox 0.9.1

  • Mozilla Firefox 0.9.2


References

CONFIRM - http://bugzilla.mozilla.org/show_bug.cgi?id=253121

XF - mozilla-ssl-certificate-spoofing(16796)

REDHAT - RHSA-2004:421

SUSE - SUSE-SA:2004:036

CONFIRM - http://www.mozilla.org/projects/security/known-vulnerabilities.html

GENTOO - GLSA-200408-22

MISC - http://www.cipher.org.uk/index.php?p=advisories/Certificate_Spoofing_Mozilla_FireFox_25-07-2004.advisory

SECUNIA - 12160

BUGTRAQ - 20040726 Mozilla Firefox Certificate Spoofing

FULLDISC - 20040725 Mozilla Firefox Certificate Spoofing

BID - 15495

FEDORA - FLSA:2089

SCO - SCOSA-2005.49


Last Updated: 27 May 2016 10:38:44