Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-0832

Опубликовано: 25 фев. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5

Описание

Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.

РелизСтатусПримечание
devel

released

36.0+build2-0ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [36.0+build2-0ubuntu0.14.04.4]]
lucid

ignored

end of life
precise

released

36.0+build2-0ubuntu0.12.04.5
trusty

released

36.0+build2-0ubuntu0.14.04.4
trusty/esm

DNE

trusty was released [36.0+build2-0ubuntu0.14.04.4]
upstream

released

36
utopic

released

36.0+build2-0ubuntu0.14.10.4

Показывать по

EPSS

Процентиль: 34%
0.00135
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.

nvd
больше 10 лет назад

Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.

debian
больше 10 лет назад

Mozilla Firefox before 36.0 does not properly recognize the equivalenc ...

github
около 3 лет назад

Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.

EPSS

Процентиль: 34%
0.00135
Низкий

5 Medium

CVSS2