RSA Signature Forgery in NSS
blog.mozilla.org
blog.mozilla.org
http://cryptopals.com/sets/6/challenges/42/
Ironically, Firefox is the only browser that had this flaw when Bleichenbacher originally described it almost 10 years ago.
I'm particularly fond of this bug; it's what started me off down the path of learning about serious crypto attacks.
This means that their flagship phone that was released only a month ago has a critical security vulnerability and there are no plans to fix it. Great work, Mozilla!
[1] - http://www.intexmobile.in/product_detail.aspx?PID=191&PCatID...
[2] - https://www.reddit.com/r/FireFoxOS/comments/2hf13o/security_...