CVE-2016-1967

MEDIUM

Mozilla Firefox <45.0 - Info Disclosure

Title source: llm

Description

Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.

Scores

CVSS v3 6.5
EPSS 0.0040
EPSS Percentile 60.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (1)

mozilla/firefox < 44.0.2

Timeline

Published Mar 13, 2016
Tracked Since Feb 18, 2026