First published: Fri Aug 05 2016(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Linux | =5.0 | |
Oracle Linux | =6 | |
Oracle Linux | =7 | |
Mozilla Firefox | <=47.0.1 | |
Mozilla Firefox ESR | =45.1.0 | |
Mozilla Firefox ESR | =45.1.1 | |
Mozilla Firefox ESR | =45.2.0 | |
Mozilla Firefox ESR | =45.3.0 | |
Mozilla Firefox | =45.1.0 | |
Mozilla Firefox | =45.1.1 | |
Mozilla Firefox | =45.2.0 | |
Mozilla Firefox | =45.3.0 | |
debian/firefox | 133.0.3-1 | |
debian/firefox-esr | 115.14.0esr-1~deb11u1 128.5.0esr-1~deb11u1 128.3.1esr-1~deb12u1 128.5.0esr-1~deb12u1 128.5.0esr-1 128.5.1esr-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5265 is a vulnerability in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 that allows user-assisted remote attackers to bypass the Same Origin Policy and conduct Universal XSS (UXSS) attacks or read arbitrary files.
CVE-2016-5265 has a severity rating of medium, with a CVSS score of 5.5.
CVE-2016-5265 affects Mozilla Firefox versions up to and including 47.0.1 and Firefox ESR versions 45.1.0, 45.1.1, 45.2.0, and 45.3.0. It also affects Oracle Linux versions 5.0, 6, and 7.
To fix CVE-2016-5265, you should update to Mozilla Firefox 48.0 or later or Firefox ESR 45.3.1 or later.
You can find more information about CVE-2016-5265 on the MITRE CVE database, Mozilla's security advisory (mfsa2016-80), and the Bugzilla entry.