ZeroHour

CVE-2016-1965

CVSS 3.0
4.3 medium
EPSS
2%p82
Published
()
Modified
Description

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

Vendors
mozillaopensuseoracle
Products
firefox, opensuse, linux
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.