VULNERABILITY INTELLIGENCE
CVE-2016-1965
CVSS score4.3 MEDIUM
EPSS probability2.21%
CISA KEVNot currently listed
Published2016-03-13
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
Primary references
- security@mozilla.org
- security@mozilla.org
- security@mozilla.org
- security@mozilla.org
- security@mozilla.org
- security@mozilla.org
- security@mozilla.org — Third Party Advisory
- security@mozilla.org
- security@mozilla.org
- security@mozilla.org — Vendor Advisory
- security@mozilla.org — Third Party Advisory
- security@mozilla.org