CVE-2015-4476

Description

Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.

Risk Information

Base Score
9.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.483

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox (41.0)Windows
Update for Mozilla Firefox (41.0.1)Windows
Update for Mozilla Firefox (41.0.2)Windows
Multiple Vulnerabilities are affected in Mozilla Firefox (x64) 40.0.3Windows
Multiple Vulnerabilities are affected in Mozilla_Firefox 40.0.3Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-302184Update for Mozilla Firefox (41.0)
PATCH-302185Update for Mozilla Firefox (41.0.1)
PATCH-302186Update for Mozilla Firefox (41.0.2)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234