CVE-2016-1940Mozilla Firefox vulnerability

CWE-173 documents3 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 44.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 31
Latest updateMay 17

Description

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

NVDmozilla/firefox43.0.4

🔴Vulnerability Details

1
GHSA
GHSA-67pg-xc6g-cjvr: Mozilla Firefox before 442022-05-17