The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade www-client/mozilla.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-bin. | Oct 30, 2017 | Feb 8, 2005 |
| Mfsa2005 29 | — | Upgrade to Mozilla Firefox version 1.0.1Upgrade to the latest version of Mozilla Firefox | Jul 28, 2005 | Feb 8, 2005 |
| Ubuntu | — | Upgrade mozilla-firefox-locale-jaUpgrade mozilla-firefoxUpgrade mozilla-firefox-locale-ukUpgrade mozilla-firefox-locale-nbUpgrade mozilla-firefox-locale-tr | Nov 8, 2024 | Feb 8, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub