4.7

CVE-2016-1947

Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 15.04
Canonical ≫ Ubuntu Linux Version 15.10
Opensuse ≫ Leap Version 42.1
Opensuse ≫ Opensuse Version 13.1
Opensuse ≫ Opensuse Version 13.2
Mozilla ≫ Firefox Version 43.0
Mozilla ≫ Firefox Version 43.0.1
Mozilla ≫ Firefox Version 43.0.2
Mozilla ≫ Firefox Version 43.0.3
Mozilla ≫ Firefox Version 43.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.93% 0.774
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.7 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://security.gentoo.org/glsa/201605-06
Third Party Advisory
VDB Entry
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00001.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00002.html
Third Party Advisory
http://www.securitytracker.com/id/1034825
http://www.ubuntu.com/usn/USN-2880-1
Third Party Advisory
http://www.ubuntu.com/usn/USN-2880-2
Third Party Advisory
http://www.mozilla.org/security/announce/2016/mfsa2016-11.html
Vendor Advisory
http://www.securityfocus.com/bid/81949
Third Party Advisory
VDB Entry
https://bugzilla.mozilla.org/show_bug.cgi?id=1237103
Vendor Advisory
Issue Tracking