Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-5282

Опубликовано: 22 сент. 2016
Источник: debian
EPSS Низкий

Описание

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed49.0-1package
firefox-esrnot-affectedpackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-86/

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-87/

EPSS

Процентиль: 60%
0.00393
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 9 лет назад

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

CVSS3: 5.6
redhat
больше 9 лет назад

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

CVSS3: 6.5
nvd
больше 9 лет назад

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

CVSS3: 6.5
github
больше 3 лет назад

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

suse-cvrf
больше 9 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS

Процентиль: 60%
0.00393
Низкий