CVE-2015-0812 — Missing Authentication for Critical Function in Mozilla Firefox
Severity
4.3MEDIUMNVD
OSV7.5
EPSS
0.1%
top 64.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 1
Latest updateMay 14
Description
Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages3 packages
Also affects: Ubuntu Linux 12.04, 14.04, 14.10
🔴Vulnerability Details
3📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2015-0812 Mozilla: Add-on lightweight theme installation approval bypassed through MITM attack (MFSA 2015-32)↗2015-03-30