CVE-2016-2810Mozilla Firefox vulnerability

CWE-2645 documents5 sources
Severity
5.0MEDIUMNVD
EPSS
0.3%
top 49.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 1.3 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

1
GHSA
GHSA-73hr-36wp-4xmc: Mozilla Firefox before 462022-05-17

📋Vendor Advisories

2
Red Hat
Mozilla: Content provider permission bypass allows malicious application to access data (MFSA 2016-41)2016-04-26
Debian
CVE-2016-2810: firefox - Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass int...2016

💬Community

1
Bugzilla
CVE-2016-2810 Mozilla: Content provider permission bypass allows malicious application to access data (MFSA 2016-41)2016-04-25