[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248678

 
 

909

 
 

195426

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-6673Date: (C)2013-12-11   (M)2024-03-27


Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.9CVSS Score : 5.8
Exploit Score: 2.2Exploit Score: 8.6
Impact Score: 3.6Impact Score: 4.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: NONEAvailability: PARTIAL
Integrity: HIGH 
Availability: NONE 
  
Reference:
SECTRACK-1029470
SECTRACK-1029476
BID-64213
FEDORA-2013-23127
FEDORA-2013-23291
FEDORA-2013-23295
FEDORA-2013-23519
GLSA-201504-01
IAVM:2013-A-0233
SUSE-SU-2013:1919
USN-2052-1
USN-2053-1
http://www.mozilla.org/security/announce/2013/mfsa2013-113.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
https://bugzilla.mozilla.org/show_bug.cgi?id=917380
openSUSE-SU-2013:1916
openSUSE-SU-2013:1917
openSUSE-SU-2013:1918
openSUSE-SU-2013:1957
openSUSE-SU-2013:1958
openSUSE-SU-2013:1959
openSUSE-SU-2014:0008

CPE    516
cpe:/a:mozilla:firefox:14.0
cpe:/o:canonical:ubuntu_linux:13.04
cpe:/a:mozilla:firefox:20.0.1
cpe:/a:mozilla:firefox:3.6.26
...
CWE    1
CWE-310
OVAL    6
oval:org.secpod.oval:def:16246
oval:org.secpod.oval:def:16262
oval:org.secpod.oval:def:701515
oval:org.secpod.oval:def:701513
...

© SecPod Technologies