Description
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-6233 | Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource. |
Ubuntu USN |
USN-3076-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T00:53:48.999Z
Reserved: 2016-06-03T00:00:00.000Z
Link: CVE-2016-5282
No data.
Status : Modified
Published: 2016-09-22T22:59:16.957
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-5282
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN