CVE-2005-2395
Summary
| CVE | CVE-2005-2395 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-07-27 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Browser Weak Authentication Mechanism Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 281851 – (httpauthorder) CVE-2005-2395 Wrong scheme used when server offers both Basic and Digest auth [rfc2617 obsoletes rfc2068] | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | |
| SecuriTeam.com ™ - Mozilla / Mozilla Firefox Authentication Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securiteam.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/19002 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Mozilla / Mozilla Firefox authentication weakness - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.