5
CVSSv2

CVE-2016-1939

Published: 31/01/2016 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Mozilla Firefox prior to 44.0 stores cookies with names containing vertical tab characters, which allows remote malicious users to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 13.1

opensuse leap 42.1

opensuse opensuse 13.2

mozilla firefox

Vendor Advisories

USN-2880-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2016-04 Firefox allows for control characters to be set in cookie names Announced January 26, 2016 Reporter musicDespiteEverything, Nicholas Hurley Impact Moderate Products Firefox F ...
Mozilla Firefox before 440 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208 ...