CVE-2024-53975

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*

History

04 Apr 2025, 16:19

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:*:iphone_os:*:*
CWE NVD-CWE-noinfo
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1843467 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1843467 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2024-66/ - () https://www.mozilla.org/security/advisories/mfsa2024-66/ - Vendor Advisory
First Time Mozilla
Mozilla firefox

27 Nov 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) Acceder a un sitio HTTP no seguro que utiliza un puerto inexistente puede provocar que el icono del candado SSL en la barra de URL de ubicación parezca seguro, de manera engañosa. Esta vulnerabilidad afecta a Firefox para iOS &lt; 133.

26 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-26 14:15

Updated : 2025-04-04 16:19


NVD link : CVE-2024-53975

Mitre link : CVE-2024-53975

CVE.ORG link : CVE-2024-53975


JSON object : View

Products Affected

mozilla

  • firefox