VulnerabilityModified
CVE-2016-5288
This vulnerability affects Firefox < 49.0.2.
MEDIUM 5.9EPSS 1.77%
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/93810Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037077Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1310183Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2016-87/Vendor Advisory
- http://www.securityfocus.com/bid/93810Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037077Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1310183Issue Tracking, Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2016-87/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.