CVE-2010-0172
Last modified
CVE-2010-0172 is a vulnerability of currently unknown severity. toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 3.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0172?
How severe is CVE-2010-0172?
How do I fix CVE-2010-0172?
Are you affected by CVE-2010-0172?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
