CVE-2011-0082
published 2011-06-06CVE-2011-0082: The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.50%
71.8th percentile
The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8fm3-gjrc-9963: The X
ghsa_unreviewed·2022-05-17
CVE-2011-0082 [MEDIUM] CWE-20 GHSA-8fm3-gjrc-9963: The X
The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
Red Hat
firefox: doesn't (re)validate certificates when loading HTTPS page
vendor_redhat·2011-05-21·CVSS 4.3
CVE-2011-0082 [MEDIUM] firefox: doesn't (re)validate certificates when loading HTTPS page
firefox: doesn't (re)validate certificates when loading HTTPS page
The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.
Package: firefox (Red Hat Enterprise Linux 4) - Not affected
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552http://openwall.com/lists/oss-security/2011/05/31/14http://openwall.com/lists/oss-security/2011/05/31/18http://openwall.com/lists/oss-security/2011/05/31/4http://openwall.com/lists/oss-security/2011/05/31/9http://www.securityfocus.com/bid/48064https://bugzilla.mozilla.org/show_bug.cgi?id=660749https://bugzilla.redhat.com/show_bug.cgi?id=709165https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14145http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=627552http://openwall.com/lists/oss-security/2011/05/31/14http://openwall.com/lists/oss-security/2011/05/31/18http://openwall.com/lists/oss-security/2011/05/31/4http://openwall.com/lists/oss-security/2011/05/31/9http://www.securityfocus.com/bid/48064https://bugzilla.mozilla.org/show_bug.cgi?id=660749https://bugzilla.redhat.com/show_bug.cgi?id=709165https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14145
2011-06-06
Published