CVE-2016-2816Improper Access Control in Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.2%
top 52.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 30
Latest updateMay 17

Description

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Ubuntumozilla/firefox< 46.0+build5-0ubuntu0.14.04.2+3
NVDmozilla/firefox45.0.2
debiandebian/firefox< firefox 46.0-1 (sid)
debiandebian/firefox-esr< firefox 46.0-1 (sid)

🔴Vulnerability Details

4
GHSA
GHSA-vhpc-6pcw-g9p4: Mozilla Firefox before 462022-05-17
OSV
firefox regression2016-05-19
OSV
firefox vulnerabilities2016-04-27
OSV
CVE-2016-2816: Mozilla Firefox before 462016-04-27

📋Vendor Advisories

5
Ubuntu
Firefox regression2016-05-19
Ubuntu
Oxygen-GTK3 update2016-05-02
Ubuntu
Firefox vulnerabilities2016-04-27
Red Hat
Mozilla: CSP not applied to pages sent with multipart/x-mixed-replace (MFSA 2016-45)2016-04-26
Debian
CVE-2016-2816: firefox - Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Securi...2016

💬Community

1
Bugzilla
CVE-2016-2816 Mozilla: CSP not applied to pages sent with multipart/x-mixed-replace (MFSA 2016-45)2016-04-25