CVE-2004-0779

Mozilla 1.6-Firefox 0.8 - Info Disclosure

Title source: llm
STIX 2.1

Description

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_mandrake
http://www.mandriva.com/security/advisories?name=MDKSA-2004:082
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=226278
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17018

Scores

EPSS 0.0211
EPSS Percentile 79.8%

Details

Status published
Products (3)
firebirdsql/firebird 0.7
mozilla/firefox 0.8
mozilla/mozilla 1.6
Published Aug 18, 2004
Tracked Since Feb 18, 2026