CVEs Blog | G5 Cyber Security

CVE-2015-0812 – Mozilla Firefox before 37.0 does not require an HTTPS session for lightwe

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0812

Reference (s):

Exit mobile version