Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade mail-client/mozilla-thunderbird.Upgrade mail-client/thunderbird.Upgrade dev-libs/nss.Upgrade www-client/seamonkey-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade www-client/firefox.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Jun 15, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub