CVE-2016-1943
published 2016-01-31CVE-2016-1943: Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
PriorityP420medium4.7CVSS 3.0
AVNACLPRNUIRSCCNILAN
EPSS
0.96%
58.0th percentile
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg2: Multiple security issues
vendor_redhat·2016-10-27·CVSS 7.5
CVE-2016-9114 [HIGH] openjpeg2: Multiple security issues
openjpeg2: Multiple security issues
There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Red Hat
Mozilla: Addressbar spoofing attacks (MFSA 2016-09)
vendor_redhat·2016-01-26·CVSS 4.7
CVE-2016-1943 [MEDIUM] Mozilla: Addressbar spoofing attacks (MFSA 2016-09)
Mozilla: Addressbar spoofing attacks (MFSA 2016-09)
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
GHSA
GHSA-gmxm-22mx-7m9q: Mozilla Firefox before 44
ghsa_unreviewed·2022-05-14
CVE-2016-1943 [MEDIUM] GHSA-gmxm-22mx-7m9q: Mozilla Firefox before 44
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.htmlhttp://www.mozilla.org/security/announce/2016/mfsa2016-09.htmlhttp://www.securityfocus.com/bid/81948http://www.securitytracker.com/id/1034825https://bugzilla.mozilla.org/show_bug.cgi?id=1228590https://security.gentoo.org/glsa/201605-06http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.htmlhttp://www.mozilla.org/security/announce/2016/mfsa2016-09.htmlhttp://www.securityfocus.com/bid/81948http://www.securitytracker.com/id/1034825https://bugzilla.mozilla.org/show_bug.cgi?id=1228590https://security.gentoo.org/glsa/201605-06
2016-01-31
Published