Lucene search

K
cvelistMozillaCVELIST:CVE-2014-8642
HistoryJan 14, 2015 - 11:00 a.m.

CVE-2014-8642

2015-01-1411:00:00
mozilla
www.cve.org
10

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

71.4%

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

71.4%