RSS   Vulnerabilities for 'Geckb'   RSS

2008-07-08
 
CVE-2008-2809

CWE-20
 

 
Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

 

 >>> Vendor: Mozilla 22 Products
Bugzilla
Mozilla
Firefox
Seamonkey
Thunderbird
Bonsai
Network security services
Camino
Mozilla suite
Durian web application server
Geckb
Libxul
NSS
Gecko
Firefox esr
Thunderbird esr
Firefox mobile
Zamboni
Firef14caox
Netscape portable runtime
Firefoxos
Firefox os


Copyright 2017, cxsecurity.com

 

Back to Top