← Back

CVE-2016-1954

nvd nist
Published: Mar 13, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.

Affected (22)

Show all products
2 products
Firefox
Thunderbird
1 product
2 products
Leap
Opensuse
1 product
Linux
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Mozilla
Up to 44.0.2
Version 38.0.1
Version 38.0.5
Version 38.0
Version 38.1.0
Version 38.1.1
Version 38.2.0
Version 38.2.1
Version 38.3.0
Version 38.4.0
Version 38.5.0
Version 38.5.1
Version 38.6.0
Version 38.6.1
Up to 38.6.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Version 12
Version 42.1
Opensuse
Version 13.1
Version 13.2
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 5.0
Version 6
Version 7

Related CWEs

References (46)

Source: security@mozilla.org
Issue TrackingPatch
Source: security@mozilla.org
Vendor Advisory
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Source: security@mozilla.org
Issue Tracking
Source: security@mozilla.org
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.