CVE Vulnerabilities

CVE-2016-1965

Published: Mar 13, 2016 | Modified: Oct 22, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 44.0.2 (including)
Firefox Mozilla 38.0 (including) 38.0 (including)
Firefox Mozilla 38.0.1 (including) 38.0.1 (including)
Firefox Mozilla 38.0.5 (including) 38.0.5 (including)
Firefox Mozilla 38.1.0 (including) 38.1.0 (including)
Firefox Mozilla 38.1.1 (including) 38.1.1 (including)
Firefox Mozilla 38.2.0 (including) 38.2.0 (including)
Firefox Mozilla 38.2.1 (including) 38.2.1 (including)
Firefox Mozilla 38.3.0 (including) 38.3.0 (including)
Firefox Mozilla 38.4.0 (including) 38.4.0 (including)
Firefox Mozilla 38.5.0 (including) 38.5.0 (including)
Firefox Mozilla 38.5.1 (including) 38.5.1 (including)
Firefox Mozilla 38.6.0 (including) 38.6.0 (including)
Firefox Mozilla 38.6.1 (including) 38.6.1 (including)
Red Hat Enterprise Linux 5 RedHat firefox-0:38.7.0-1.el5_11 *
Red Hat Enterprise Linux 6 RedHat firefox-0:38.7.0-1.el6_7 *
Red Hat Enterprise Linux 7 RedHat firefox-0:38.7.0-1.el7_2 *
Firefox Ubuntu precise *
Firefox Ubuntu trusty *
Firefox Ubuntu upstream *
Firefox Ubuntu wily *

References