CVE Vulnerabilities

CVE-2007-1762

Published: Mar 30, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla2.0.0.1 (including)2.0.0.1 (including)
FirefoxMozilla2.0.0.2 (including)2.0.0.2 (including)
FirefoxMozilla2.0.0.3 (including)2.0.0.3 (including)
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntuedgy*
FirefoxUbuntufeisty*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*

References