Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox "HTTP Host"报头 中间人攻击和信息泄露漏洞
Vulnerability Description
Firefox是Mozilla所发布的开源WEB浏览器 。 Firefox中的多个安全漏洞,由于代码共享,Thunderbird和SeaMonkey也受这些漏洞的影响 。在处理到代理的CONNECT请求后的非200响应时存在错误,如果攻击者能够对使用代理服务器的Firefox例程执行中间人攻击,就可以从用户所访问的站点窃取敏感信息 。
CVSS Information
N/A
Vulnerability Type
N/A