Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade thunderbirdUpgrade seamonkeyUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade libxulUpgrade linux-thunderbirdUpgrade firefoxUpgrade firefox-esr | Dec 10, 2025 | Feb 1, 2016 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade dev-libs/nss.Upgrade www-client/firefox.Upgrade dev-libs/nspr.Upgrade www-client/firefox-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Jan 31, 2016 |
| Mfsa2016 09 | — | Upgrade to Mozilla Firefox version 44.0Upgrade to the latest version of Mozilla Firefox | Jan 26, 2016 | Jan 26, 2016 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-common | Feb 2, 2016 | Jan 31, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub