If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the …
Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability was fi…
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as hav…
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thu…
If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server that used that certificate, and…
When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificate error. …
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is …
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav…
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was…
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service.
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an admini…
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those ar…
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perfor…
The contribution feature in Zamboni does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltNam…
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properl…