Unrated severityNVD Advisory· Published Jul 27, 2005· Updated Jun 16, 2026
CVE-2005-2395
CVE-2005-2395
Description
Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:firefox:1.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:firefox:1.0.5:*:*:*:*:*:*:*
- (no CPE)range: 1.0.4 - 1.0.5
Patches
Vulnerability mechanics
References
7News mentions
0No linked articles in our index yet.