The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2004-08-14T04:00:00
Updated: 2024-08-08T00:31:46.860Z
Reserved: 2004-08-13T00:00:00
Link: CVE-2004-0779
Vulnrichment
No data.
NVD
Status : Modified
Published: 2004-08-18T04:00:00.000
Modified: 2024-11-20T23:49:23.103
Link: CVE-2004-0779
Redhat
No data.