CVE-2016-2829Improper Access Control in Firefox

Severity
6.5MEDIUMNVD
OSV8.8
EPSS
0.4%
top 41.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages6 packages

Ubuntumozilla/firefox< 47.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox46.0.1
debiandebian/firefox< firefox 47.0-1 (sid)
debiandebian/firefox-esr< firefox 47.0-1 (sid)
NVDopensuse/leap42.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-4jxh-294h-xrm7: Mozilla Firefox before 472022-05-14
OSV
firefox vulnerabilities2016-06-09
OSV
CVE-2016-2829: Mozilla Firefox before 472016-06-08

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-06-09
Red Hat
Mozilla: Incorrect icon displayed on permissions notifications (MFSA 2016-57)2016-06-07
Debian
CVE-2016-2829: firefox - Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifica...2016

💬Community

1
Bugzilla
CVE-2016-2829 Mozilla: Incorrect icon displayed on permissions notifications (MFSA 2016-57)2016-06-06