Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-0834

Опубликовано: 25 фев. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

РелизСтатусПримечание
devel

released

36.0+build2-0ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [36.0+build2-0ubuntu0.14.04.4]]
lucid

ignored

end of life
precise

released

36.0+build2-0ubuntu0.12.04.5
trusty

released

36.0+build2-0ubuntu0.14.04.4
trusty/esm

DNE

trusty was released [36.0+build2-0ubuntu0.14.04.4]
upstream

released

36
utopic

released

36.0+build2-0ubuntu0.14.10.4

Показывать по

EPSS

Процентиль: 66%
0.00514
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

nvd
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

debian
почти 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: ...

github
больше 3 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

EPSS

Процентиль: 66%
0.00514
Низкий

4.3 Medium

CVSS2