4.3
CVSSv2

CVE-2014-1584

Published: 15/10/2014 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Public Key Pinning (PKP) implementation in Mozilla Firefox prior to 33.0 skips pinning checks upon an unspecified issuer-verification error, which makes it easier for remote malicious users to bypass an intended pinning configuration and spoof a web site via a crafted certificate that leads to presentation of the Untrusted Connection dialog to the user.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 30.0

mozilla firefox 31.1.0

mozilla firefox 31.0

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2014-80 Key pinning bypasses Announced October 14, 2014 Reporter Patrick McManus, David Keeler Impact Moderate Products Firefox, SeaMonkey Fixed in ...
The Public Key Pinning (PKP) implementation in Mozilla Firefox before 330 skips pinning checks upon an unspecified issuer-verification error, which makes it easier for remote attackers to bypass an intended pinning configuration and spoof a web site via a crafted certificate that leads to presentation of the Untrusted Connection dialog to the user ...