CVE-2016-5265 — Cross-site Scripting in Mozilla Firefox
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 50.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 5
Latest updateMay 13
Description
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.
CVSS vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 1.0 | Impact: 4.0
Affected Packages2 packages
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2016-5265 Mozilla: Same-origin policy violation using local HTML file and saved shortcut file (MFSA 2016-80)↗2016-08-01