Lucene search

K
cve[email protected]CVE-2015-7208
HistoryDec 16, 2015 - 11:59 a.m.

CVE-2015-7208

2015-12-1611:59:07
CWE-200
web.nvd.nist.gov
40
cve-2015-7208
mozilla firefox
security vulnerability
http cookie headers
sensitive information exposure

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.5%

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.

Affected configurations

NVD
Node
mozillafirefoxRange42.0
Node
fedoraprojectfedoraMatch22
OR
fedoraprojectfedoraMatch23
Node
opensuseleapMatch42.1
OR
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
CPENameOperatorVersion
mozilla:firefoxmozilla firefoxle42.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.5%