Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cm2-qg89-qv3m

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

EPSS

Процентиль: 66%
0.00514
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

redhat
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

nvd
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

debian
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: ...

EPSS

Процентиль: 66%
0.00514
Низкий

Дефекты

CWE-200