Lucene search

K
cve[email protected]CVE-2004-0867
HistoryDec 23, 2004 - 5:00 a.m.

CVE-2004-0867

2004-12-2305:00:00
CWE-264
web.nvd.nist.gov
24
mozilla
firefox
0.9.2
session fixation
cookies
security vulnerability
nvd
cve-2004-0867

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.7%

Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user’s HTTP session. NOTE: it was later reported that 2.x is also affected.

Affected configurations

NVD
Node
kdekonquerorMatch2.1.1
OR
kdekonquerorMatch2.1.2
OR
kdekonquerorMatch2.2.1
OR
kdekonquerorMatch2.2.2
OR
kdekonquerorMatch3.0
OR
kdekonquerorMatch3.0.1
OR
kdekonquerorMatch3.0.2
OR
kdekonquerorMatch3.0.3
OR
kdekonquerorMatch3.0.5
OR
kdekonquerorMatch3.0.5b
OR
kdekonquerorMatch3.1
OR
kdekonquerorMatch3.1.1
OR
kdekonquerorMatch3.1.2
OR
kdekonquerorMatch3.1.3
OR
kdekonquerorMatch3.1.4
OR
kdekonquerorMatch3.1.5
OR
kdekonquerorMatch3.2.1
OR
kdekonquerorMatch3.2.3
OR
microsoftieMatch6.0sp1
OR
microsoftieMatch6.0sp2
OR
microsoftinternet_explorerMatch6.0
OR
mozillafirefoxMatch0.9.2
Node
susesuse_linuxMatch1.0desktop
OR
susesuse_linuxMatch8enterprise_server
OR
susesuse_linuxMatch8.1
OR
susesuse_linuxMatch8.2
OR
susesuse_linuxMatch9.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

High

0.017 Low

EPSS

Percentile

87.7%