CVE-2015-4476 — Improper Input Validation in Mozilla Firefox
Severity
4.3MEDIUMNVD
EPSS
0.5%
top 34.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17
Description
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages1 packages
🔴Vulnerability Details
1📋Vendor Advisories
1Red Hat▶
Mozilla: Site attribute spoofing on Android by pasting URL with unknown scheme (MFSA 2015-99)↗2015-09-22