The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 does not properly set the minimum key length for Diffie-Hellman Ephemeral (DHE) mode, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade seamonkey-nsprUpgrade seamonkey-chatUpgrade nss-toolsUpgrade seamonkey-nssUpgrade nssUpgrade seamonkey-dom-inspectorUpgrade seamonkey-nspr-develUpgrade firefoxUpgrade xulrunnerUpgrade nss-develUpgrade seamonkey-develUpgrade seamonkey-js-debuggerUpgrade seamonkey-mailUpgrade nss-pkcs11-develUpgrade seamonkey-nss-develUpgrade seamonkeyUpgrade xulrunner-devel | Dec 1, 2016 | Oct 21, 2010 |
| Debian | — | Upgrade nss | Jul 30, 2024 | Oct 21, 2010 |
| Freebsd | — | Upgrade linux-firefoxUpgrade firefoxUpgrade linux-firefox-develUpgrade libxulUpgrade thunderbirdUpgrade seamonkey | Dec 10, 2025 | Oct 20, 2010 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade www-client/icecat.Upgrade www-client/firefox.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin.Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird-bin.Upgrade www-client/seamonkey-bin.Upgrade net-libs/xulrunner-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Oct 21, 2010 |
| Mfsa2010 72 | — | Upgrade to Mozilla Firefox version 3.6.11Upgrade to Mozilla Firefox version 3.5.14 | Jun 14, 2012 | Oct 21, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.9 | Feb 3, 2012 | Oct 21, 2010 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.1.5Upgrade to Mozilla Thunderbird version 3.0.9 | Feb 22, 2012 | Oct 21, 2010 |
| Oracle_linux | — | Upgrade nss-develUpgrade nssUpgrade xulrunner-develUpgrade firefoxUpgrade nss-pkcs11-develUpgrade nss-toolsUpgrade xulrunner | Oct 16, 2024 | Oct 21, 2010 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 19, 2010 |
| Suse | — | Upgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-32bitUpgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-commonUpgrade MozillaFirefox-translationsUpgrade MozillaFirefox-translations-commonUpgrade mozilla-xulrunner192-gnome-32bitUpgrade MozillaThunderbirdUpgrade MozillaFirefox-translations-otherUpgrade mozilla-xulrunner192Upgrade MozillaThunderbird-develUpgrade MozillaFirefox-develUpgrade MozillaThunderbird-translations-otherUpgrade mozilla-xulrunner192-develUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192-gnome | Dec 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade libnss3-1d | Nov 8, 2024 | Oct 21, 2010 |
| Vmsa 2011 0013 | — | Upgrade VMware ESX 4.1 to build number 502767 | Nov 22, 2011 | Oct 21, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub