4.3
CVSSv2

CVE-2016-1948

Published: 31/01/2016 Updated: 10/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle malicious users to replace a theme's images and colors by modifying the client-server data stream.

Vulnerable Product Search on Vulmon Subscribe to Product

google android

mozilla firefox 43.0.4

Vendor Advisories

Mozilla Foundation Security Advisory 2016-12 Lightweight themes on Firefox for Android do not verify a secure connection Announced January 26, 2016 Reporter Margaret Leibovic Impact Low Products Firefox Fixed in ...