CVE-2016-5262Cross-site Scripting in Mozilla Firefox

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 5
Latest updateMay 13

Description

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDmozilla/firefox47.0.1+4
NVDoracle/linux5.0, 6, 7+2

🔴Vulnerability Details

3
GHSA
GHSA-3qpq-w8fc-xx86: Mozilla Firefox before 482022-05-13
CVEList
CVE-2016-5262: Mozilla Firefox before 482016-08-05
OSV
CVE-2016-5262: Mozilla Firefox before 482016-08-05

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-08-05
Red Hat
Mozilla: Scripts on marquee tag can execute in sandboxed iframes (MFSA 2016-76)2016-08-02
Debian
CVE-2016-5262: firefox - Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript ...2016

💬Community

1
Bugzilla
CVE-2016-5262 Mozilla: Scripts on marquee tag can execute in sandboxed iframes (MFSA 2016-76)2016-08-01
CVE-2016-5262 — Cross-site Scripting in Mozilla Firefox | cvebase