VulnerabilityModified
CVE-2016-2825
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
MEDIUM 6.5EPSS 1.70%
Does this matter?
Lower severity and a low EPSS score (1.70%). Track it; it rarely justifies an emergency change on its own.
Description
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- canonical/ubuntu linux · opensuse/leap · opensuse/opensuse · mozilla/firefox
- Source
- security@mozilla.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-54.htmlVendor Advisory
- http://www.securitytracker.com/id/1036057
- http://www.ubuntu.com/usn/USN-2993-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1193093
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00016.html
- http://www.mozilla.org/security/announce/2016/mfsa2016-54.htmlVendor Advisory
- http://www.securitytracker.com/id/1036057
- http://www.ubuntu.com/usn/USN-2993-1
- https://bugzilla.mozilla.org/show_bug.cgi?id=1193093
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.