cbcvebase.
CVE-2004-0765
published 2004-08-18

CVE-2004-0765: The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when…

PriorityP422high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.03%
60.5th percentile
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

Affected

3 ranges
VendorProductVersion rangeFixed in
mozillafirefox<= 0.9
mozillamozilla<= 1.7
mozillathunderbird<= 0.7

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.