Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Moxie Marlinspike

#20682of 53,633
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2014-5455
6.4
2014-10-22
Pidgin · Libpurple · CVE-2014-3694
**Name of the Vulnerable Software and Affected Versions** Pidgin versions prior to 2.10.10 **Description** The issue arises from the improper consideration of the Basic Constraints extension during the verification of X.509 certificates from SSL servers by the bundled GnuTLS and OpenSSL SSL/TLS plugins in libpurple. This allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. **Recommendations** For versions prior to 2.10.10, update to version 2.10.10 or later to resolve the issue.
PT-2009-3293
5.8
2009-02-20
Mozilla · Thunderbird · CVE-2009-0652
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 3.0.9 Thunderbird versions prior to 2.0.0.21 SeaMonkey versions prior to 1.1.15 **Description** The issue allows remote attackers to spoof URLs and conduct phishing attacks by using box-drawing characters not included in the Internationalized Domain Names (IDN) blacklist. This can be demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name. **Recommendations** For Mozilla Firefox versions prior to 3.0.9, update to version 3.0.9 or later. For Thunderbird versions prior to 2.0.0.21, update to version 2.0.0.21 or later. For SeaMonkey versions prior to 1.1.15, update to version 1.1.15 or later.