The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade net-libs/xulrunner-bin.Upgrade www-client/seamonkey.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade www-client/seamonkey-bin.Upgrade www-client/icecat.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner.Upgrade mail-client/thunderbird.Upgrade dev-libs/nss.Upgrade mail-client/mozilla-thunderbird-bin. | Oct 30, 2017 | Dec 9, 2010 |
| Suse | — | Upgrade operaUpgrade opera-gtkUpgrade opera-kde4 | Feb 17, 2015 | Dec 9, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub