Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox 代码注入漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 36.0.4及之前版本中存在安全漏洞,该漏洞源于程序在轻量级主题的附加组件安装过程中没有要求使用HTTPS会话。攻击者可通过部署特制的Web网站并对mozilla.org子域实施DNS欺骗攻击,利用该漏洞实施中间人攻击,绕过既定的user-confirmation要求。
CVSS Information
N/A
Vulnerability Type
N/A