Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-libs/nss.Upgrade www-client/mozilla-firefox.Upgrade www-client/seamonkey.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird.Upgrade net-libs/xulrunner-bin.Upgrade www-client/firefox-bin.Upgrade net-libs/xulrunner.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/icecat.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox-bin. | Oct 30, 2017 | Jun 15, 2009 |
| Ubuntu | — | Upgrade xulrunner-1.9Upgrade seamonkeyUpgrade xulrunner-1.9.1 | Nov 19, 2024 | Jun 15, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub