CVE Database
/

CVE-2005-0593

Back to search

CVE-2005-0593

Published: Feb 28, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.

VendorProductVersions

n/a

n/a

affected
n/a

References

12659
vdb-entry
x_refsource_BID
oval:org.mitre.oval:def:100044
vdb-entry
signature
x_refsource_OVAL
RHSA-2005:176
vendor-advisory
x_refsource_REDHAT
oval:org.mitre.oval:def:9533
vdb-entry
signature
x_refsource_OVAL
RHSA-2005:384
vendor-advisory
x_refsource_REDHAT
GLSA-200503-30
vendor-advisory
x_refsource_GENTOO
GLSA-200503-10
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now