CVE-2016-2822Improper Access Control in Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.7%
top 28.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

Ubuntumozilla/firefox< 47.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox46.0.1+2
debiandebian/firefox< firefox 47.0-1 (sid)
debiandebian/firefox-esr< firefox 47.0-1 (sid)
NVDopensuse/leap42.1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-6g5m-4924-79vh: Mozilla Firefox before 472022-05-14
OSV
CVE-2016-2822: Mozilla Firefox before 472016-06-13
OSV
firefox vulnerabilities2016-06-09

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-06-09
Red Hat
Mozilla: Addressbar spoofing though the SELECT element (MFSA 2016-52)2016-06-08
Debian
CVE-2016-2822: firefox - Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attack...2016

💬Community

3
Bugzilla
CVE-2016-8608 Stored XSS in business process editor2016-10-19
Bugzilla
CVE-2016-7041 Drools Workbench: Path traversal vulnerability2016-09-13
Bugzilla
CVE-2016-2822 Mozilla: Addressbar spoofing though the SELECT element (MFSA 2016-52)2016-06-06