Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-4809

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2005-4809
Last Modified 07 Mar 2011 09:29:02
Published 31 Dec 2005 12:00:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-4809

Summary

Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.

Vulnerable Systems

Application

  • Mozilla 1.7.3

  • Mozilla 1.7.4

  • Mozilla 1.7.5

  • Mozilla 1.7.6

  • Mozilla Firefox 0.10

  • Mozilla Firefox 0.10.1

  • Mozilla Firefox 0.8

  • Mozilla Firefox 0.9

  • Mozilla Firefox 0.9.1

  • Mozilla Firefox 0.9.2

  • Mozilla Firefox 0.9.3

  • Mozilla Firefox 1.0

  • Mozilla Firefox 1.0.1

  • Mozilla Firefox Preview Release

  • Mozilla Thunderbird 0.6

  • Mozilla Thunderbird 0.7

  • Mozilla Thunderbird 0.7.1

  • Mozilla Thunderbird 0.7.2

  • Mozilla Thunderbird 0.7.3

  • Mozilla Thunderbird 0.8

  • Mozilla Thunderbird 0.9

  • Mozilla Thunderbird 1.0

  • Mozilla Thunderbird 1.0.1


References

XF - mozilla-save-link-as-dialog-spoofing(19540)

VUPEN - ADV-2005-0260

BID - 12798

OSVDB - 14885

SECTRACK - 1013423

SECUNIA - 14568

FULLDISC - 20050313 Firefox 1.01 : spoofing status bar without using JavaScript


Last Updated: 27 May 2016 10:41:26