CVE-2004-0779
Last modified
CVE-2004-0779 is a vulnerability of currently unknown severity. The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Firebirdsql | Firebird | 0.7 |
| Mozilla | Firefox | 0.8 |
| Mozilla | Mozilla | 1.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0779?
How severe is CVE-2004-0779?
How do I fix CVE-2004-0779?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0771Buffer overflow in the extract_one function from lhext.c in …
- CVE-2004-0772Double free vulnerabilities in error handling code in krb524…9.8
- CVE-2004-0774RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.…
- CVE-2004-0775Buffer overflow in WIDCOMM Bluetooth Connectivity Software, …
- CVE-2004-0777Format string vulnerability in the auth_debug function in Co…
- CVE-2004-0778CVS 1.11.x before 1.11.17, and 1.12.x before 1.12.9, allows …
- CVE-2004-0780Buffer overflow in uustat in Sun Solaris 8 and 9 allows loca…
- CVE-2004-0781Cross-site scripting (XSS) vulnerability in list.cgi in the …
- CVE-2004-0782Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the…
- CVE-2004-0783Stack-based buffer overflow in xpm_extract_color (io-xpm.c) …
- CVE-2004-0784The smiley theme functionality in Gaim before 0.82 allows re…
- CVE-2004-0785Multiple buffer overflows in Gaim before 0.82 allow remote a…
Are you affected by CVE-2004-0779?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
