Vulnerability Name: | CVE-2011-0082 (CCN-67784) | ||||||||
Assigned: | 2010-12-21 | ||||||||
Published: | 2011-06-01 | ||||||||
Updated: | 2017-09-19 | ||||||||
Summary: | The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.5 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
3.5 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: CONFIRM Type: Exploit http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552 Source: MITRE Type: CNA CVE-2011-0082 Source: MLIST Type: Exploit [oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page Source: MLIST Type: Exploit [oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page Source: MLIST Type: Exploit [oss-security] 20110531 CVE request: firefox doesn't (re)validate certificates when loading HTTPS page Source: MLIST Type: Exploit [oss-security] 20110531 Re: CVE request: firefox doesn't (re)validate certificates when loading HTTPS page Source: CCN Type: Mozilla Web site mozilla - home of the mozilla, firefox, and camino web browsers Source: CCN Type: OSVDB ID: 74378 Mozilla Firefox X.509 Certificate Validation Single-session Security Exception SSL Server Spoofing Weakness Source: BID Type: UNKNOWN 48064 Source: CCN Type: BID-48064 Mozilla Firefox SSL Certificate Validation Security Weakness Source: CCN Type: Bugzilla@Mozilla Bug 660749 (CVE-2011-0082) Firefox doesn't (re)validate certificates when loading HTTPS page Source: CONFIRM Type: Exploit https://bugzilla.mozilla.org/show_bug.cgi?id=660749 Source: CONFIRM Type: Exploit https://bugzilla.redhat.com/show_bug.cgi?id=709165 Source: XF Type: UNKNOWN mozilla-firefox-ssl-sec-bypass(67784) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:14145 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |