CVE-2016-1965: Medium severity firefox vulnerability
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1965?
CVE-2016-1965 is rated as moderate in severity, as it allows potential address bar spoofing.
How do I fix CVE-2016-1965?
To fix CVE-2016-1965, update Mozilla Firefox to version 45.0 or later, or Firefox ESR to 38.7 or later.
Which versions of Firefox are affected by CVE-2016-1965?
CVE-2016-1965 affects Firefox versions before 45.0 and Firefox ESR versions prior to 38.7.
What type of attack can CVE-2016-1965 facilitate?
CVE-2016-1965 can facilitate address bar spoofing through a navigation sequence that returns to the original page.
Is there a workaround for CVE-2016-1965?
There are no known workarounds for CVE-2016-1965, so it is recommended to update the browser.