VulnerabilityModified
CVE-2016-1947
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
MEDIUM 4.7EPSS 1.93%
Does this matter?
Lower severity and a low EPSS score (1.93%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- EPSS
- 1.93% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- canonical/ubuntu linux · opensuse/leap · opensuse/opensuse · mozilla/firefox
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2016/mfsa2016-11.htmlVendor Advisory
- http://www.securityfocus.com/bid/81949Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034825
- http://www.ubuntu.com/usn/USN-2880-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2880-2Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1237103Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201605-06Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.htmlThird Party Advisory
- http://www.mozilla.org/security/announce/2016/mfsa2016-11.htmlVendor Advisory
- http://www.securityfocus.com/bid/81949Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034825
- http://www.ubuntu.com/usn/USN-2880-1Third Party Advisory
- http://www.ubuntu.com/usn/USN-2880-2Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1237103Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201605-06Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.