Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html
http://www.mozilla.org/security/announce/2016/mfsa2016-09.html
http://www.securityfocus.com/bid/81948
http://www.securitytracker.com/id/1034825
http://www.ubuntu.com/usn/USN-2880-1
http://www.ubuntu.com/usn/USN-2880-2
Source: MITRE
Published: 2016-01-31
Updated: 2018-10-30
Type: CWE-20
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 7.4
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
Impact Score: 4
Exploitability Score: 2.8
Severity: HIGH
OR
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 43.0.4 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
802019 | Firefox < 44 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | critical |
91379 | GLSA-201605-06 : Mozilla Products: Multiple vulnerabilities (Logjam) (SLOTH) | Nessus | Gentoo Local Security Checks | critical |
9075 | Mozilla Firefox < 44.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
88637 | Ubuntu 12.04 LTS / 14.04 LTS / 15.10 : firefox regression (USN-2880-2) | Nessus | Ubuntu Local Security Checks | critical |
88552 | openSUSE Security Update : Mozilla Firefox (openSUSE-2016-131) | Nessus | SuSE Local Security Checks | critical |
88549 | openSUSE Security Update : the MozillaFirefox / mozilla-nss and mozilla-nspr (openSUSE-2016-128) | Nessus | SuSE Local Security Checks | critical |
88512 | FreeBSD : mozilla -- multiple vulnerabilities (4f00dac0-1e18-4481-95af-7aaad63fd303) | Nessus | FreeBSD Local Security Checks | critical |
88461 | Firefox < 44 Multiple Vulnerabilities | Nessus | Windows | critical |
88459 | Firefox < 44 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | critical |
88456 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 / 15.10 : firefox vulnerabilities (USN-2880-1) | Nessus | Ubuntu Local Security Checks | critical |