Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5268

Опубликовано: 05 авг. 2016
Источник: debian
EPSS Низкий

Описание

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed48.0-1package
firefox-esrnot-affectedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-83/

EPSS

Процентиль: 66%
0.01228
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
около 10 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
redhat
около 10 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
nvd
около 10 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
github
больше 4 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

fstec
около 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 66%
0.01228
Низкий