CVE-2016-3276
published 2016-07-13CVE-2016-3276: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing…
PriorityP416low3.1CVSS 3.0
AVNACHPRNUIRSUCNILAN
EPSS
7.22%
93.6th percentile
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| msrc | microsoft_edge_on_windows_10_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_for_x64-based_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1511_for_32-bit_systems | — | — |
| msrc | microsoft_edge_on_windows_10_version_1511_for_x64-based_systems | — | — |
| shadow_project | shadow | >= 0 < 1:4.1.5.1-1ubuntu9.5 | 1:4.1.5.1-1ubuntu9.5 |
| shadow_project | shadow | >= 0 < 1:4.2-3.1ubuntu5.3 | 1:4.2-3.1ubuntu5.3 |
CVSS provenance
nvdv3.03.1LOWCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
osv7.8HIGH
vendor_msrc3.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Browser Spoofing Vulnerability
vendor_msrc·2016-07-12·CVSS 3.1
CVE-2016-3276 [LOW] Microsoft Browser Spoofing Vulnerability
Microsoft Browser Spoofing Vulnerability
Description: A spoofing vulnerability exists when Microsoft browsers do not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content or serve as a pivot to chain an attack with other vulnerabilities in web services.
To exploit the vulnerability, the user must click a specially crafted URL. In an email attack scenario, an attacker could send an email message containing the specially crafted URL to the user in an attempt to convince the user to click it.
In a web-based attack scenario, an attacker could host a specially crafted website designed to appear as a legitimate website to the user.
GHSA
GHSA-cq9j-7r3r-xrff: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser
ghsa_unreviewed·2022-05-14
CVE-2016-3276 [LOW] CWE-284 GHSA-cq9j-7r3r-xrff: Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
OSV
shadow regression
osv·2017-05-17·CVSS 7.8
CVE-2016-6252 shadow regression
shadow regression
USN-3276-1 intended to fix a vulnerability in su. The solution introduced
a regression in su signal handling. This update modifies the security fix.
We apologize for the inconvenience.
Original advisory details:
Sebastian Krahmer discovered integer overflows in shadow utilities.
A local attacker could possibly cause them to crash or potentially
gain privileges via crafted input. (CVE-2016-6252)
Tobias Stöckmann discovered a race condition in su. A local
attacker could cause su to send SIGKILL to other processes with
root privileges. (CVE-2017-2616)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/91593http://www.securitytracker.com/id/1036283https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-084https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-085http://www.securityfocus.com/bid/91593http://www.securitytracker.com/id/1036283https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-084https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-085
2016-07-13
Published