CVE-2016-5268

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
05/08/2016
Last modified:
12/04/2025

Description

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* 47.0.1 (including)