Vulnerability Description
Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 0.8 |
References
- http://marc.info/?l=bugtraq&m=110547286002188&w=2
- http://secunia.com/advisories/13786
- http://www.gentoo.org/security/en/glsa/glsa-200503-10.xmlPatchVendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200503-30.xmlPatchVendor Advisory
- http://www.mikx.de/firespoofing/Exploit
- http://www.mikx.de/index.php?p=7Vendor Advisory
- http://www.mozilla.org/security/announce/mfsa2005-16.html
- http://www.redhat.com/support/errata/RHSA-2005-176.html
- http://www.redhat.com/support/errata/RHSA-2005-384.html
- http://www.securityfocus.com/bid/12234
- https://bugzilla.mozilla.org/show_bug.cgi?id=260560Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18864
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://marc.info/?l=bugtraq&m=110547286002188&w=2
FAQ
What is CVE-2005-0591?
CVE-2005-0591 is a vulnerability with a CVSS score of 2.6 (LOW). Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file...
How severe is CVE-2005-0591?
CVE-2005-0591 has been rated LOW with a CVSS base score of 2.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0591?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.