7.5
CVSSv2

CVE-2005-0147

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Firefox prior to 1.0 and Mozilla prior to 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote malicious users to steal NTLM or SPNEGO credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla mozilla 1.7

mozilla mozilla 1.7.1

mozilla firefox 0.9

mozilla firefox 0.9.1

mozilla firefox 0.9.2

mozilla firefox 0.9.3

mozilla firefox 0.8

mozilla mozilla 1.7.2

mozilla mozilla 1.7.3

Vendor Advisories

Synopsis mozilla security update Type/Severity Security Advisory: Critical Topic Updated mozilla packages that fix various bugs are now availableThis update has been rated as having critical security impact by the RedHat Security Response Team Description Mozilla is an open source Web bro ...
USN-149-1 fixed some vulnerabilities in the Ubuntu 504 (Hoary Hedgehog) version of Firefox The version shipped with Ubuntu 410 (Warty Warthog) is also vulnerable to these flaws, so it needs to be upgraded as well Please see ...