The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-nspr-develUpgrade nssUpgrade nss-toolsUpgrade firefoxUpgrade seamonkey-nsprUpgrade seamonkey-nssUpgrade seamonkey-dom-inspectorUpgrade seamonkey-chatUpgrade xulrunner-develUpgrade seamonkey-nss-develUpgrade nss-pkcs11-develUpgrade nss-develUpgrade seamonkeyUpgrade xulrunnerUpgrade seamonkey-develUpgrade seamonkey-js-debuggerUpgrade seamonkey-mail | Dec 1, 2016 | Oct 21, 2010 |
| Debian | — | Upgrade nss | Jul 30, 2024 | Oct 21, 2010 |
| Freebsd | — | Upgrade linux-firefoxUpgrade linux-firefox-develUpgrade thunderbirdUpgrade seamonkeyUpgrade libxulUpgrade firefox | Dec 10, 2025 | Oct 20, 2010 |
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird.Upgrade net-libs/xulrunner.Upgrade www-client/firefox-bin.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade dev-libs/nss.Upgrade www-client/seamonkey.Upgrade www-client/mozilla-firefox.Upgrade www-client/icecat. | Oct 30, 2017 | Oct 21, 2010 |
| Mfsa2010 72 | — | Upgrade to Mozilla Firefox version 3.6.11Upgrade to Mozilla Firefox version 3.5.14 | Jun 14, 2012 | Oct 21, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.9 | Feb 3, 2012 | Oct 21, 2010 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.1.5Upgrade to Mozilla Thunderbird version 3.0.9 | Feb 22, 2012 | Oct 21, 2010 |
| Oracle_linux | — | Upgrade firefoxUpgrade xulrunnerUpgrade nss-pkcs11-develUpgrade nss-toolsUpgrade xulrunner-develUpgrade nssUpgrade nss-devel | Oct 16, 2024 | Oct 21, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 19, 2010 |
| Suse | — | Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-x86Upgrade MozillaThunderbird-translations-otherUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192Upgrade mozilla-xulrunner192-gnomeUpgrade mozilla-xulrunner192-translations-32bitUpgrade MozillaThunderbirdUpgrade mozilla-xulrunner192-translationsUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefoxUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner192-gnome-32bitUpgrade MozillaFirefox-translations-other | Dec 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libnss3-1d | Nov 8, 2024 | Oct 21, 2010 |
| Vmsa 2011 0013 | — | Upgrade VMware ESX 4.1 to build number 502767 | Nov 22, 2011 | Oct 21, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub