CVE-2016-5298 describes a vulnerability in Firefox for Android versions prior to 50, where interrupting a new page load could cause the previous page's favicon and SSL indicator to persist. This medium-severity vulnerability (CVSS 6.5) requires user interaction and could lead to a spoofing attack, as a user might mistakenly believe they are on a secure site. There is no evidence of active exploitation, and no public exploit code or Metasploit modules are available, with minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 50.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 50CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.