Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xiasijie12345

#51763of 53,633
4.3Total CVSS
Vulnerabilities · 1
PT-2013-6070
4.3
2013-12-10
Mozilla · Firefox · CVE-2013-6673
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 26.0 Firefox ESR versions 24.x prior to 24.2 Thunderbird versions prior to 24.2 SeaMonkey versions prior to 2.23 **Description** The issue makes it easier for man-in-the-middle attackers to spoof SSL servers via a valid but unacceptable certificate. This occurs because the software does not recognize a user's removal of trust from an EV X.509 certificate. **Recommendations** For Mozilla Firefox versions prior to 26.0, update to version 26.0 or later. For Firefox ESR versions 24.x prior to 24.2, update to version 24.2 or later. For Thunderbird versions prior to 24.2, update to version 24.2 or later. For SeaMonkey versions prior to 2.23, update to version 2.23 or later.