Description
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
Published: 2004-08-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2004-0777 The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
History

No history.

Subscriptions

Firebirdsql Firebird
Mozilla Firefox Mozilla
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-08T00:31:46.860Z

Reserved: 2004-08-13T00:00:00.000Z

Link: CVE-2004-0779

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2004-08-18T04:00:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2004-0779

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses