UCF STIG Viewer Logo

Mozilla Firefox


Overview

Date Finding Count (55)
2017-03-22 CAT I (High): 2 CAT II (Med): 53 CAT III (Low): 0
STIG Description
The Mozilla Firefox Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil

Available Profiles



Findings (MAC III - Administrative Sensitive)

Finding ID Severity Title
V-17988 High Installed version of Firefox unsupported.
V-57663 High Installed version of Firefox unsupported.
V-15986 Medium Firefox is configured to allow JavaScript to disable or replace context menus.
V-57675 Medium Default behavior must block webpages from automatically running plugins.
V-57677 Medium Extensions must be disabled by default.
V-57671 Medium Prevent the Deletion of Browsing Data
V-57673 Medium Disable Firefox Sync
V-57605 Medium Firefox is configured to allow use of SSL 2.0.
V-57679 Medium Disable Firefox crash reporter.
V-15773 Medium FireFox plug-in for ActiveX controls is installed.
V-15985 Medium Firefox is configured to allow JavaScript to raise or lower windows.
V-57659 Medium Firefox is not configured to provide warnings when a user switches from a secure (SSL-enabled) to a non-secure page.
V-6318 Medium The DOD Root Certificate is not installed.
V-15777 Medium Firefox does not clear cookies upon closing.
V-57651 Medium Firefox is configured to allow JavaScript to change the status bar text.
V-15987 Medium Firefox is configured to allow JavaScript to hide or change the status bar.
V-15988 Medium Firefox is configured to allow JavaScript to change the status bar text.
V-57587 Medium Network shell protocol is enabled in Firefox.
V-57585 Medium Firefox automatically executes or downloads MIME types which are not authorized for auto-download.
V-57597 Medium Firefox is configured to use a password store with or without a master password.
V-57583 Medium Firefox is configured to ask which certificate to present to a web site when a certificate is required.
V-57581 Medium Firefox is configured to allow use of SSL 3.0.
V-19743 Medium Firefox required security preferences cannot be changed by user.
V-19742 Medium Firefox automatically updates installed add-ons and plugins.
V-19741 Medium Firefox application is set to auto-update.
V-57589 Medium Firefox not configured to prompt user before download and opening for required file types.
V-19744 Medium Firefox automatically checks for updated version of installed Search plugins.
V-15768 Medium FireFox is configured to ask which certificate to present to a web site when a certificate is required.
V-15983 Medium Firefox must be configured to allow only TLS.
V-15771 Medium Network shell protocol is enabled in FireFox.
V-57579 Medium The DOD Root Certificate is not installed.
V-57667 Medium Firefox automatically updates installed add-ons and plugins.
V-57665 Medium Firefox application is set to auto-update.
V-57669 Medium Firefox automatically checks for updated version of installed Search plugins.
V-57681 Medium Auto-complete must be disabled
V-57661 Medium The Firefox browser home page is not set to blank or a trusted site.
V-57649 Medium Firefox is configured to allow JavaScript to hide or change the status bar.
V-64891 Medium Extensions install must be disabled.
V-57607 Medium Firefox is not configured to allow use of TLS 1.0 and above.
V-57601 Medium Firefox is not configured to block pop-up windows.
V-57603 Medium Firefox is configured to allow JavaScript to move or resize windows.
V-57643 Medium Firefox is configured to allow JavaScript to raise or lower windows.
V-57647 Medium Firefox is configured to allow JavaScript to disable or replace context menus.
V-15776 Medium FireFox is configured to use a password store with or without a master password.
V-57595 Medium Firefox is configured to autofill passwords.
V-15774 Medium Firefox formfill assistance option is disabled.
V-15775 Medium Firefox is configured to autofill passwords.
V-15772 Medium Firefox not configured to prompt user before download and opening for required file types.
V-57591 Medium Firefox plugin for ActiveX controls is installed.
V-15770 Medium Firefox automatically executes or downloads MIME types which are not authorized for auto-download.
V-57593 Medium Firefox formfill assistance option is disabled.
V-15989 Medium Firefox is not configured to provide warnings when a user switches from a secure (SSL-enabled) to a non-secure page.
V-57599 Medium Firefox does not clear cookies upon closing.
V-15778 Medium FireFox is not configured to block pop-up windows.
V-15779 Medium FireFox is configured to allow JavaScript to move or resize windows.