5
CVSSv2

CVE-2015-0832

Published: 25/02/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle malicious users to bypass the HPKP and HSTS protection mechanisms by constructing a URL with this character and leveraging access to an X.509 certificate for a domain with this character.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.2

opensuse opensuse 13.1

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 14.10

mozilla firefox 30.0

mozilla firefox 3.6.9

mozilla firefox 3.6.27

mozilla firefox 3.6.26

mozilla firefox 3.6.2

mozilla firefox 3.6.19

mozilla firefox 3.6.11

mozilla firefox 3.6.10

mozilla firefox 3.5.4

mozilla firefox 3.5.3

mozilla firefox 3.5.14

mozilla firefox 3.5.13

mozilla firefox 3.0.7

mozilla firefox 3.0.6

mozilla firefox 3.0.17

mozilla firefox 3.0.16

mozilla firefox 3.0.1

mozilla firefox 3.0

mozilla firefox 25.0

mozilla firefox 24.1.1

mozilla firefox 20.0.1

mozilla firefox 20.0

mozilla firefox 2.0.0.3

mozilla firefox 2.0.0.20

mozilla firefox 2.0.0.2

mozilla firefox 2.0.0.13

mozilla firefox 2.0.0.12

mozilla firefox 19.0

mozilla firefox 18.0.2

mozilla firefox 17.0.4

mozilla firefox 17.0.3

mozilla firefox 16.0.1

mozilla firefox 16.0

mozilla firefox

mozilla firefox 3.6.8

mozilla firefox 3.6.7

mozilla firefox 3.6.25

mozilla firefox 3.6.24

mozilla firefox 3.6.18

mozilla firefox 3.6.17

mozilla firefox 3.6

mozilla firefox 3.5.9

mozilla firefox 3.5.2

mozilla firefox 3.5.19

mozilla firefox 3.5.12

mozilla firefox 3.5.11

mozilla firefox 3.0.5

mozilla firefox 3.0.4

mozilla firefox 3.0.15

mozilla firefox 3.0.14

mozilla firefox 29.0.1

mozilla firefox 29.0

mozilla firefox 28.0

mozilla firefox 24.1

mozilla firefox 24.0

mozilla firefox 2.0.0.9

mozilla firefox 2.0.0.8

mozilla firefox 2.0.0.19

mozilla firefox 2.0.0.18

mozilla firefox 2.0.0.11

mozilla firefox 2.0.0.10

mozilla firefox 18.0.1

mozilla firefox 18.0

mozilla firefox 32.0

mozilla firefox 31.1.0

mozilla firefox 31.0

mozilla firefox 3.6.3

mozilla firefox 3.6.28

mozilla firefox 3.6.21

mozilla firefox 3.6.20

mozilla firefox 3.6.13

mozilla firefox 3.6.12

mozilla firefox 3.5.6

mozilla firefox 3.5.5

mozilla firefox 3.5.16

mozilla firefox 3.5.15

mozilla firefox 3.0.9

mozilla firefox 3.0.8

mozilla firefox 3.0.19

mozilla firefox 3.0.18

mozilla firefox 3.0.11

mozilla firefox 3.0.10

mozilla firefox 26.0

mozilla firefox 25.0.1

mozilla firefox 22.0

mozilla firefox 21.0

mozilla firefox 2.0.0.5

mozilla firefox 2.0.0.4

mozilla firefox 2.0.0.15

mozilla firefox 2.0.0.14

mozilla firefox 19.0.2

mozilla firefox 19.0.1

mozilla firefox 17.0.7

mozilla firefox 17.0.6

mozilla firefox 17.0.5

mozilla firefox 17.0

mozilla firefox 16.0.2

mozilla firefox 13.0.1

mozilla firefox 13.0

mozilla firefox 10.0.5

mozilla firefox 10.0.4

mozilla firefox 10.0

mozilla firefox 4.0

mozilla firefox 6.0

mozilla firefox 6.0.1

mozilla firefox 9.0.1

mozilla firefox 1.8

mozilla firefox 1.5.2

mozilla firefox 1.5.1

mozilla firefox 1.5.0.2

mozilla firefox 1.5.0.12

mozilla firefox 1.4.1

mozilla firefox 1.0.8

mozilla firefox 1.0.1

mozilla firefox 1.0

mozilla firefox 0.7.1

mozilla firefox 0.7

mozilla firefox 0.10.1

mozilla firefox 0.10

mozilla firefox 17.0.2

mozilla firefox 17.0.11

mozilla firefox 15.0.1

mozilla firefox 15.0

mozilla firefox 11.0

mozilla firefox 10.0.9

mozilla firefox 10.0.12

mozilla firefox 10.0.11

mozilla firefox 7.0.1

mozilla firefox 8.0

mozilla firefox 1.5.6

mozilla firefox 1.5.5

mozilla firefox 1.5.0.7

mozilla firefox 1.5.0.6

mozilla firefox 1.5.0.5

mozilla firefox 1.5.0.1

mozilla firefox 1.5

mozilla firefox 1.0.5

mozilla firefox 1.0.4

mozilla firefox 0.9.1

mozilla firefox 0.9

mozilla firefox 0.5

mozilla firefox 0.4

mozilla firefox 12.0

mozilla firefox 10.0.3

mozilla firefox 10.0.2

mozilla firefox 6.0.2

mozilla firefox 7.0

mozilla firefox 1.5.8

mozilla firefox 1.5.7

mozilla firefox 1.5.0.9

mozilla firefox 1.5.0.8

mozilla firefox 1.5.0.11

mozilla firefox 1.5.0.10

mozilla firefox 1.0.7

mozilla firefox 1.0.6

mozilla firefox 0.9.3

mozilla firefox 0.9.2

mozilla firefox 0.6.1

mozilla firefox 0.6

mozilla firefox 0.1

mozilla firefox 34.0.5

mozilla firefox 33.0

mozilla firefox 3.6.6

mozilla firefox 3.6.4

mozilla firefox 3.6.23

mozilla firefox 3.6.22

mozilla firefox 3.6.16

mozilla firefox 3.6.15

mozilla firefox 3.6.14

mozilla firefox 3.5.8

mozilla firefox 3.5.7

mozilla firefox 3.5.18

mozilla firefox 3.5.17

mozilla firefox 3.5.10

mozilla firefox 3.5.1

mozilla firefox 3.5

mozilla firefox 3.0.3

mozilla firefox 3.0.2

mozilla firefox 3.0.13

mozilla firefox 3.0.12

mozilla firefox 27.0.1

mozilla firefox 27.0

mozilla firefox 23.0.1

mozilla firefox 23.0

mozilla firefox 2.0.0.7

mozilla firefox 2.0.0.6

mozilla firefox 2.0.0.17

mozilla firefox 2.0.0.16

mozilla firefox 2.0.0.1

mozilla firefox 2.0

mozilla firefox 17.0.9

mozilla firefox 17.0.8

mozilla firefox 17.0.10

mozilla firefox 17.0.1

mozilla firefox 14.0.1

mozilla firefox 14.0

mozilla firefox 10.0.8

mozilla firefox 10.0.7

mozilla firefox 10.0.6

mozilla firefox 10.0.10

mozilla firefox 10.0.1

mozilla firefox 4.0.1

mozilla firefox 5.0

mozilla firefox 5.0.1

mozilla firefox 8.0.1

mozilla firefox 9.0

mozilla firefox 1.5.4

mozilla firefox 1.5.3

mozilla firefox 1.5.0.4

mozilla firefox 1.5.0.3

mozilla firefox 1.0.3

mozilla firefox 1.0.2

mozilla firefox 0.8

mozilla firefox 0.3

mozilla firefox 0.2

Vendor Advisories

USN-2505-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2015-13 Appended period to hostnames can bypass HPKP and HSTS protections Announced February 24, 2015 Reporter Muneaki Nishimura Impact Moderate Products Firefox, Firefox OS, SeaMonkey ...