Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2005 09 | — | Upgrade to Mozilla Firefox version 1.0.0Upgrade to the latest version of Mozilla Firefox | Jul 28, 2005 | May 2, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-trUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-nbUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-ja | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub