CVE-2015-7208Sensitive Information Exposure in Mozilla Firefox

Severity
5.3MEDIUMNVD
NVD5.0OSV10.0OSV5.0
EPSS
0.6%
top 29.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 14

Description

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

Ubuntumozilla/firefox< 44.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox43.0.4+1
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

Also affects: Fedora 22, 23

🔴Vulnerability Details

5
GHSA
GHSA-m3g3-73hc-9hqr: Mozilla Firefox before 432022-05-14
GHSA
GHSA-r5m5-v5v5-wq3f: Mozilla Firefox before 442022-05-14
OSV
CVE-2016-1939: Mozilla Firefox before 442016-01-26
OSV
CVE-2015-7208: Mozilla Firefox before 432015-12-15
OSV
firefox vulnerabilities2015-12-15

📋Vendor Advisories

3
Red Hat
Mozilla: Firefox allows for control characters to be set in cookie names (MFSA 2016-04)2016-01-26
Red Hat
Mozilla: Firefox allows for control characters to be set in cookies (MFSA 2015-137)2015-12-16
Ubuntu
Firefox vulnerabilities2015-12-15

💬Community

1
Bugzilla
CVE-2015-7208 Mozilla: Firefox allows for control characters to be set in cookies (MFSA 2015-137)2015-12-15
CVE-2015-7208 — Sensitive Information Exposure | cvebase