CVE-2016-1948 PUBLISHED CVSS 5.300000190734863 MEDIUM

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.

EPSS 0.22% · 44.4th percentile

Risk Scores

CVSS v3.0
5.300000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.22%
44.4th percentile

Affected Products

VendorProductVersions
mozillafirefox43.0.4
n/an/an/a
googleandroid

Timeline

References

Open in Interactive Console →