Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a malicious site and accepting a malicious certificate for the Mozilla update site, which can then be used to install arbitrary code on the next update.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade thunderbird | Jul 30, 2024 | Sep 15, 2006 |
| Freebsd | — | Upgrade mozilla-thunderbirdUpgrade linux-mozilla-develUpgrade linux-firefox-develUpgrade thunderbirdUpgrade firefoxUpgrade linux-seamonkey-develUpgrade mozillaUpgrade linux-seamonkeyUpgrade seamonkeyUpgrade linux-thunderbirdUpgrade linux-mozillaUpgrade linux-firefox | Dec 10, 2025 | Sep 15, 2006 |
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/mozilla-firefox.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Sep 15, 2006 |
| Mfsa2006 58 | — | Upgrade to Mozilla Firefox version 1.5.0.7 | Nov 21, 2013 | Sep 15, 2006 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 1.5.0.7 | Nov 21, 2013 | Sep 15, 2006 |
| Ubuntu | — | Upgrade mozilla-thunderbird-locale-nlUpgrade mozilla-thunderbird-locale-frUpgrade mozilla-thunderbird-locale-plUpgrade firefoxUpgrade mozilla-thunderbird-locale-caUpgrade mozilla-thunderbird-locale-itUpgrade mozilla-thunderbird-typeaheadfindUpgrade libnss3Upgrade mozilla-thunderbird-enigmailUpgrade mozilla-thunderbirdUpgrade mozilla-thunderbird-inspectorUpgrade mozilla-thunderbird-locale-deUpgrade mozilla-thunderbird-locale-uk | Nov 8, 2024 | Sep 15, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub