CVE-2016-1958 describes a spoofing vulnerability in Mozilla Firefox versions prior to 45.0 and Firefox ESR 38.x before 38.7, affecting various Linux distributions. An attacker could exploit this flaw by using a javascript: URL to manipulate the address bar, potentially deceiving users about the true origin of a webpage. This vulnerability carries a CVSS v3 score of 4.3 (MEDIUM), indicating a network-based attack requiring user interaction, with a low impact on integrity and no impact on confidentiality or availability. While the exploit complexity is low, it relies on social engineering to trick the user. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei. The vulnerability has received minimal community discussion and media coverage, suggesting a low profile and limited interest from attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:oracle:linux:5.0:*:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:o:oracle:linux:6:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:o:oracle:linux:7:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
<= 44.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.