Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade firefoxUpgrade linux-firefoxUpgrade firefox-esrUpgrade linux-seamonkeyUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade libxul | Dec 10, 2025 | Jan 14, 2015 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade www-client/seamonkey.Upgrade www-client/firefox-bin.Upgrade www-client/seamonkey-bin.Upgrade dev-libs/nspr.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Jan 14, 2015 |
| Mfsa2015 08 | — | Upgrade to Mozilla Firefox version 35.0Upgrade to the latest version of Mozilla Firefox | Jan 15, 2015 | Jan 13, 2015 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.32.0 | Jan 15, 2015 | Jan 13, 2015 |
| Oracle Solaris | — | Upgrade runtime/tcl-8/tcl-sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3 to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade database/sqlite-3/documentation to version 3.9.2-0.175.3.8.0.2.0 on Solaris 11.3Upgrade web/browser/firefox to version 38.4.0-0.175.3.8.0.2.0 on Solaris 11.3 | May 29, 2017 | Jan 14, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 15, 2015 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-devel | Dec 18, 2015 | Jan 14, 2015 |
| Ubuntu | — | Upgrade firefox | Nov 8, 2024 | Jan 14, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub