Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-0765

Опубликовано: 18 авг. 2004
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
Версия до 0.9 (включая)
cpe:2.3:a:mozilla:mozilla:*:*:*:*:*:*:*:*
Версия до 1.7 (включая)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Версия до 0.7 (включая)

EPSS

Процентиль: 72%
0.00766
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

redhat
больше 21 года назад

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

debian
почти 21 год назад

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0 ...

github
около 3 лет назад

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

EPSS

Процентиль: 72%
0.00766
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other