Mozilla Firefox < 1.7 Multiple Remote Overflows

critical Nessus Network Monitor Plugin ID 1239

Synopsis

The remote browser is vulnerable to multiple overflow flaws.

Description

The remote host is using the Mozilla web browser prior to version 1.7. There are several flaws within this version of Mozilla that include a remote overflow via a spoofed address bar, an overflow in the SSL certificate store, and other serious issues.

Solution

Upgrade to Firefox 1.7 or later.

See Also

http://www.mozilla.org/security

Plugin Details

Severity: Critical

ID: 1239

Family: Web Clients

Published: 8/20/2004

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Reference Information

CVE: CVE-2004-0757

BID: 15495