SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-1965

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the…

MEDIUM 4.3EPSS 2.21%

Does this matter?

Lower severity and a low EPSS score (2.21%). Track it; it rarely justifies an emergency change on its own.

Description

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS
2.21% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-254
Affected
mozilla/firefox · opensuse/opensuse · oracle/linux
Source
security@mozilla.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.