CVE-2016-1942

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.

References

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html

http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html

http://www.mozilla.org/security/announce/2016/mfsa2016-09.html

http://www.securityfocus.com/bid/81948

http://www.securitytracker.com/id/1034825

http://www.ubuntu.com/usn/USN-2880-1

http://www.ubuntu.com/usn/USN-2880-2

https://bugzilla.mozilla.org/show_bug.cgi?id=1189082

https://security.gentoo.org/glsa/201605-06

Details

Source: MITRE

Published: 2016-01-31

Updated: 2018-10-30

Type: CWE-20

Risk Information

CVSS v2

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

Impact Score: 4

Exploitability Score: 2.8

Severity: HIGH

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
802019Firefox < 44 Multiple VulnerabilitiesLog Correlation EngineWeb Clients
critical
91379GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH)NessusGentoo Local Security Checks
critical
9075Mozilla Firefox < 44.0 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
88637Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : firefox regression (USN-2880-2)NessusUbuntu Local Security Checks
critical
88552openSUSE Security Update : Mozilla Firefox (openSUSE-2016-131)NessusSuSE Local Security Checks
critical
88549openSUSE Security Update : the MozillaFirefox / mozilla-nss and mozilla-nspr (openSUSE-2016-128)NessusSuSE Local Security Checks
critical
88512FreeBSD : mozilla -- multiple vulnerabilities (4f00dac0-1e18-4481-95af-7aaad63fd303)NessusFreeBSD Local Security Checks
critical
88461Firefox < 44 Multiple VulnerabilitiesNessusWindows
critical
88459Firefox < 44 Multiple Vulnerabilities (Mac OS X)NessusMacOS X Local Security Checks
critical
88456Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : firefox vulnerabilities (USN-2880-1)NessusUbuntu Local Security Checks
critical