CVE-2016-5265

MEDIUM

Oracle Linux < 47.0.1 - Information Disclosure

Title source: rule

Description

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 49.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

Classification

CWE
CWE-79 CWE-200
Status draft

Affected Products (8)

oracle/linux
oracle/linux
oracle/linux
mozilla/firefox < 47.0.1
mozilla/firefox
mozilla/firefox
mozilla/firefox
mozilla/firefox

Timeline

Published Aug 05, 2016
Tracked Since Feb 18, 2026