CVE Database
/

CVE-2016-5282

Back to search

CVE-2016-5282

Published: Sep 22, 2016

Modified: Aug 6, 2024

PUBLISHED

Description

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

VendorProductVersions

n/a

n/a

affected
n/a

References

93052
vdb-entry
x_refsource_BID
GLSA-201701-15
vendor-advisory
x_refsource_GENTOO
1036852
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now