CVE-2016-5283 — Improper Access Control in Firefox
Severity
8.8HIGHNVD
OSV6.5
EPSS
0.3%
top 49.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 22
Latest updateMay 17
Description
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2016-5283 Mozilla: iframe src fragment timing attack can reveal cross-origin data (MFSA 2016-85)↗2016-09-20