« Back to list

CVE-2005-4809

Status: ModifiedMedium (5)—💥 Exploit

Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

Affected technologies (3)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2005-4809",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=full-disclosure&m=111073068631287&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/14568",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1013423",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/14885",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/12798",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2005/0260",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/19540",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=full-disclosure&m=111073068631287&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/14568",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1013423",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/14885",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/12798",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2005/0260",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/19540",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag."
    }
  ],
  "lastModified": "2026-06-16T22:19:29.610",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93C142C5-3A85-432B-80D6-2E7B1B4694F4"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2434FCE7-A50B-4527-9970-C7224B31141C"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.9:rc:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5633FB6E-D623-49D4-9858-4E20E64DE458"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "429ECA02-DBCD-45FB-942C-CA4BC1BC8A72"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5F0DC80-5473-465C-9D7F-9589F1B78E12"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "567FF916-7DE0-403C-8528-7931A43E0D18"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "010B34F4-910E-4515-990B-8E72DF009578"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:0.10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8FAA1A89-E8D9-46D0-8E2C-9259920ACBFE"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A545A77-2198-4685-A87F-E0F2DAECECF6"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "778FAE0C-A5CF-4B67-93A9-1A803E3E699F"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:firefox:preview_release:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CFDBA992-46F8-42A6-9428-C9E475CA69E3"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C883B45F-D28D-428E-AAF7-F93522A229DC"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.7.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78647043-8EBD-48AA-98F4-8E6D332C35E6"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFA659B9-2A00-45A6-A462-4E0A20FB7F81"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:mozilla:1.7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFC06EBA-A836-4817-AEF6-EAC4BEDDF3CB"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E2A68B4-9101-4AC5-9E82-EEB5A5405541"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDA6C390-9BA7-4355-8C0A-CD68FF6AC236"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C75B125-E5BB-49A0-B12D-6CF40D8A5DB7"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70DDB53E-7A12-4A08-8999-DB68E6DF901E"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6514EDE8-7C78-4C72-A313-E0915D89E4EF"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5263F879-9B90-4582-B677-F133DEBE5259"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C256B73C-9ABC-43D4-8C57-09161BC9F923"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "055D1044-9FC5-45AA-8407-649E96C5AFE3"
            },
            {
              "criteria": "cpe:2.3:a:mozilla:thunderbird:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7C1C87A5-C14D-4A23-B865-3BB1FCDC8470"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}