The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows remote attackers to obtain passwords via a password INPUT element on a different web page located on the web site intended for this password.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade mozillaUpgrade linux-mozillaUpgrade thunderbirdUpgrade linux-firefox-develUpgrade linux-thunderbirdUpgrade linux-seamonkey-develUpgrade linux-seamonkeyUpgrade lightningUpgrade linux-mozilla-develUpgrade firefox-jaUpgrade firefoxUpgrade mozilla-thunderbirdUpgrade seamonkeyUpgrade linux-firefox | Dec 10, 2025 | Feb 24, 2007 |
| Gentoo Linux | — | Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey-bin.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Nov 24, 2006 |
| Mfsa2007 02 | — | Upgrade to Mozilla Firefox version 2.0.0.2Upgrade to Mozilla Firefox version 1.5.0.10 | Jun 14, 2012 | Nov 24, 2006 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.0.8 | Feb 3, 2012 | Nov 24, 2006 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-other | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libnss3Upgrade libnspr4Upgrade firefox | Nov 8, 2024 | Nov 24, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub