The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-seamonkeyUpgrade libxulUpgrade firefoxUpgrade firefox-esr | Dec 10, 2025 | Apr 26, 2016 |
| Gentoo Linux | — | Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Apr 30, 2016 |
| Mfsa2016 48 | — | Upgrade to Mozilla Firefox version 46.0Upgrade to the latest version of Mozilla Firefox | Apr 27, 2016 | Apr 26, 2016 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-develUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox | May 4, 2016 | Apr 30, 2016 |
| Ubuntu | — | Upgrade firefox | Apr 30, 2016 | Apr 30, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub