CVE-2015-7195 PUBLISHED

The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect.

EPSS 0.56% · 68.2th percentile

Risk Scores

EPSS Score
0.56%
68.2th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSfirefox0, 24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1

Timeline

References

Open in Interactive Console →