CVE-2016-2832Sensitive Information Exposure in Firefox

Severity
4.3MEDIUMNVD
OSV8.8
EPSS
0.4%
top 37.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages6 packages

Ubuntumozilla/firefox< 47.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox46.0.1
debiandebian/firefox< firefox 47.0-1 (sid)
debiandebian/firefox-esr< firefox 47.0-1 (sid)
NVDopensuse/leap42.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-5j93-vr94-vf49: Mozilla Firefox before 472022-05-14
OSV
firefox vulnerabilities2016-06-09
OSV
CVE-2016-2832: Mozilla Firefox before 472016-06-08

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-06-09
Red Hat
Mozilla: Information disclosure of disabled plugins through CSS pseudo-classes (MFSA 2016-60)2016-06-07
Debian
CVE-2016-2832: firefox - Mozilla Firefox before 47.0 allows remote attackers to discover the list of disa...2016

💬Community

1
Bugzilla
CVE-2016-2832 Mozilla: Information disclosure of disabled plugins through CSS pseudo-classes (MFSA 2016-60)2016-06-06