4.3
CVSSv2

CVE-2015-4476

Published: 24/09/2015 Updated: 22/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 41.0 on Android allows user-assisted remote malicious users to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Mozilla Foundation Security Advisory 2015-99 Site attribute spoofing on Android by pasting URL with unknown scheme Announced September 22, 2015 Reporter Jordi Chancel Impact Moderate Products Firefox Fixed in ...
Mozilla Firefox before 410 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute ...