CVE-2016-2813

Description

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a devices physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.472

Associated Vulnerability

VulnerabilityOS Platform
Update for Mozilla Firefox (46.0)Windows
Update for Mozilla Firefox x64 (46.0)Windows
Update for Mozilla Firefox (46.0.1)Windows
Update for Mozilla Firefox x64 (46.0.1)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-302208Update for Mozilla Firefox x64 (46.0)
PATCH-344482Mozilla Firefox (134.0.1)
PATCH-302210Update for Mozilla Firefox x64 (46.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234