CVE-2016-5279: Infoleak
Last updated 24 July 2024
Other sources
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
— Launchpad
The full path to local files is available to scripts when local files are drag and dropped into Firefox.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability CVE-2016-5279?
CVE-2016-5279 is a vulnerability in Mozilla Firefox before 49.0 that allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
Which software products are affected by CVE-2016-5279?
Mozilla Firefox before version 49.0 is affected by CVE-2016-5279.
What is the severity of CVE-2016-5279?
CVE-2016-5279 has a medium severity.
How can I fix CVE-2016-5279 in Mozilla Firefox?
To fix CVE-2016-5279, update Mozilla Firefox to version 49.0 or later.
Where can I find more information about CVE-2016-5279?
You can find more information about CVE-2016-5279 on the following references: [link1](https://bugzilla.mozilla.org/show_bug.cgi?id=1249522), [link2](https://www.mozilla.org/en-US/security/advisories/mfsa2016-85/), [link3](http://www.mozilla.org/security/announce/2016/mfsa2016-85.html).