4.3

CVE-2011-0082

Exploit
The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version 4.0
Mozilla ≫ Firefox Version 4.0 Update beta1
Mozilla ≫ Firefox Version 4.0 Update beta10
Mozilla ≫ Firefox Version 4.0 Update beta11
Mozilla ≫ Firefox Version 4.0 Update beta12
Mozilla ≫ Firefox Version 4.0 Update beta2
Mozilla ≫ Firefox Version 4.0 Update beta3
Mozilla ≫ Firefox Version 4.0 Update beta4
Mozilla ≫ Firefox Version 4.0 Update beta5
Mozilla ≫ Firefox Version 4.0 Update beta6
Mozilla ≫ Firefox Version 4.0 Update beta7
Mozilla ≫ Firefox Version 4.0 Update beta8
Mozilla ≫ Firefox Version 4.0 Update beta9
Mozilla ≫ Firefox Version 4.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.5% 0.71
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552
Exploit
http://openwall.com/lists/oss-security/2011/05/31/14
Exploit
http://openwall.com/lists/oss-security/2011/05/31/18
Exploit
http://openwall.com/lists/oss-security/2011/05/31/4
Exploit
http://openwall.com/lists/oss-security/2011/05/31/9
Exploit
http://www.securityfocus.com/bid/48064
https://bugzilla.mozilla.org/show_bug.cgi?id=660749
Exploit
https://bugzilla.redhat.com/show_bug.cgi?id=709165
Exploit
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14145