CVE-2005-0591: Low severity Mozilla Firefox vulnerability
Published Feb 28, 2005
·Updated
Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
Affected Software
9 affected components
Mozilla Firefox=0.8
Mozilla Firefox=0.9
Mozilla Firefox=0.9-rc
Mozilla Firefox=0.9.1
Mozilla Firefox=0.9.2
Mozilla Firefox=0.9.3
Mozilla Firefox=0.10
Mozilla Firefox=0.10.1
Mozilla Firefox=1.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Feb 28, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0591?
CVE-2005-0591 is considered a high severity vulnerability as it allows remote attackers to spoof critical dialog boxes.
2
How do I fix CVE-2005-0591?
To fix CVE-2005-0591, users should upgrade to Firefox version 1.0.1 or later.
3
What versions of Firefox are affected by CVE-2005-0591?
CVE-2005-0591 affects Firefox versions 0.8 to 1.0, inclusive.
4
What type of attack does CVE-2005-0591 enable?
CVE-2005-0591 enables attackers to execute script or download harmful files by spoofing security dialogs.
5
Is there a workaround for CVE-2005-0591 if I cannot upgrade Firefox?
There is no official workaround for CVE-2005-0591; upgrading is the recommended solution.