Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade xulrunner-develUpgrade thunderbirdUpgrade firefoxUpgrade xulrunnerUpgrade xulrunner-devel-unstable | Dec 1, 2016 | Jun 12, 2009 |
| Freebsd | — | Upgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-firefox-develUpgrade linux-firefoxUpgrade firefoxUpgrade seamonkeyUpgrade linux-thunderbird | Dec 10, 2025 | Jun 12, 2009 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/icecat.Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner.Upgrade dev-libs/nss. | Oct 30, 2017 | Jun 12, 2009 |
| Mfsa2009 27 | — | Upgrade to Mozilla Firefox version 3.0.10 | Jun 14, 2012 | Jun 12, 2009 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 1.1.17 | Feb 3, 2012 | Jun 12, 2009 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 2.0.0.22 | Feb 22, 2012 | Jun 12, 2009 |
| Oracle_linux | — | Upgrade firefoxUpgrade xulrunner-develUpgrade xulrunnerUpgrade xulrunner-devel-unstable | Oct 16, 2024 | Jun 12, 2009 |
| Suse | — | Upgrade libfreebl3-32bitUpgrade mozilla-xulrunner191Upgrade mozilla-xulrunner190Upgrade mozilla-xulrunner190-32bitUpgrade mozilla-xulrunner190-translationsUpgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefoxUpgrade orbit2-32bitUpgrade gconf2-x86Upgrade mozilla-nss-32bitUpgrade mozilla-xulrunner191-gnomevfsUpgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner190-x86Upgrade libidlUpgrade mozilla-xulrunner192-translationsUpgrade gconf2Upgrade mozilla-nspr-x86Upgrade mozilla-nss-toolsUpgrade mozilla-nss-x86Upgrade mozilla-nsprUpgrade orbit2-x86Upgrade mozilla-xulrunner191-translationsUpgrade libfreebl3-x86Upgrade mozilla-nssUpgrade mozilla-xulrunner192-gnomeUpgrade orbit2Upgrade MozillaFirefox-branding-SLEDUpgrade libfreebl3Upgrade mozilla-xulrunner190-gnomevfsUpgrade libidl-32bitUpgrade mozilla-nspr-32bitUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner191-x86Upgrade mozilla-xulrunner191-32bitUpgrade mozilla-xulrunner192Upgrade gconf2-32bitUpgrade libidl-x86 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade abrowserUpgrade thunderbirdUpgrade firefox-3.0 | Nov 8, 2024 | Jun 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub