CVE-2016-2809Mozilla Firefox vulnerability

CWE-2645 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.4%
top 39.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

1
GHSA
GHSA-4qq8-cxv5-977h: The Mozilla Maintenance Service updater in Mozilla Firefox before 462022-05-17

📋Vendor Advisories

2
Red Hat
Mozilla: Privilege escalation through file deletion by Maintenance Service updater (MFSA 2016-40)2016-04-26
Debian
CVE-2016-2809: firefox - The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Window...2016

💬Community

1
Bugzilla
CVE-2016-2809 Mozilla: Privilege escalation through file deletion by Maintenance Service updater (MFSA 2016-40)2016-04-25