Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade firefox | Nov 14, 2016 | Oct 21, 2016 |
| Mfsa2016 87 | — | Upgrade to Mozilla Firefox version 49.0.2 | Oct 25, 2016 | Oct 20, 2016 |
| Suse | — | Upgrade mozillafirefox-develUpgrade mozillafirefoxUpgrade mozillafirefox-translations-otherUpgrade mozillafirefox-translations-common | Oct 26, 2016 | Oct 26, 2016 |
| Ubuntu | — | Upgrade firefox | Oct 27, 2016 | Oct 26, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub