CVE-2016-5265Cross-site Scripting in Mozilla Firefox

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 50.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 5
Latest updateMay 13

Description

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 1.0 | Impact: 4.0

Affected Packages2 packages

NVDmozilla/firefox47.0.1+4
NVDoracle/linux5.0, 6, 7+2

🔴Vulnerability Details

3
GHSA
GHSA-vf6c-g2gw-jg5r: Mozilla Firefox before 482022-05-13
OSV
CVE-2016-5265: Mozilla Firefox before 482016-08-05
CVEList
CVE-2016-5265: Mozilla Firefox before 482016-08-05

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-08-05
Red Hat
Mozilla: Same-origin policy violation using local HTML file and saved shortcut file (MFSA 2016-80)2016-08-02
Debian
CVE-2016-5265: firefox - Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted...2016

💬Community

1
Bugzilla
CVE-2016-5265 Mozilla: Same-origin policy violation using local HTML file and saved shortcut file (MFSA 2016-80)2016-08-01
CVE-2016-5265 — Cross-site Scripting in Mozilla Firefox | cvebase