CVE-2015-2741: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.3% chance of exploitation in the next 30 days.

Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.

Affected products

  • Mozilla Firefox: up to and including 38.1.0; version 31.0 only; version 31.1.0 only; version 31.1.1 only; version 31.3.0 only; version 31.5.1 only; …
  • Mozilla Firefox ESR: version 31.1 only; version 31.2 only; version 31.3 only; version 31.4 only; version 31.5 only; version 31.6.0 only; …
  • Oracle Solaris: version 11.3 only

Published 2015-07-06. Last modified 2026-06-17.