Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2025-6433

около 1 года назад

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2025-6433

около 1 года назад

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 3.4
EPSS: Низкий
nvd логотип

CVE-2025-6433

около 1 года назад

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-6433

около 1 года назад

If a user visited a webpage with an invalid TLS certificate, and grant ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7f3m-mqm5-5x2c

около 1 года назад

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2025-07649

около 1 года назад

Уязвимость реализации протокола TLS браузера Mozilla Firefox, позволяющая нарушителю обойти существующие ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02339-1

около 1 года назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02546-1

около 1 года назад

Security update for MozillaThunderbird

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02529-1

около 1 года назад

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 3.4
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.

CVSS3: 9.8
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-6433

If a user visited a webpage with an invalid TLS certificate, and grant ...

CVSS3: 9.8
0%
Низкий
около 1 года назад
github логотип
GHSA-7f3m-mqm5-5x2c

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.

CVSS3: 9.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-07649

Уязвимость реализации протокола TLS браузера Mozilla Firefox, позволяющая нарушителю обойти существующие ограничения безопасности и получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02339-1

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02546-1

Security update for MozillaThunderbird

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02529-1

Security update for MozillaFirefox, MozillaFirefox-branding-SLE

около 1 года назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.