CVE-2015-7211 — Improper Input Validation in Mozilla Firefox
Severity
5.0MEDIUMNVD
OSV10.0
EPSS
0.7%
top 28.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 14
Description
Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.
CVSS vector
AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages4 packages
Also affects: Fedora 22, 23