CVE-2015-4476Improper Input Validation in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 34.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17

Description

Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/firefox40.0.3

🔴Vulnerability Details

1
GHSA
GHSA-jj3v-jj5r-gj49: Mozilla Firefox before 412022-05-17

📋Vendor Advisories

1
Red Hat
Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)2015-09-22

💬Community

2
Bugzilla
Custom URI schemes in the location bar can lead to Location Bar Spoofing2016-12-25
Bugzilla
CVE-2015-4476 Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)2015-09-23