CVE-2015-0812

Description

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

Risk Information

Base Score
3.1
MODERATE
Vector
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS Score
Exploitation Probability
0.148

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Mozilla Firefox (x64) 36.0.4Windows
Multiple vulnerabilities affected in Mozilla_Firefox 36.0.4Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (137.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (137.0.1)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (137.0.2)Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 36.0.4Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-343016Mozilla Firefox (x64) (132.0.2)
PATCH-343015Mozilla Firefox (132.0.2)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234