Unrated severityNVD Advisory· Published Nov 5, 2015· Updated May 6, 2026
CVE-2015-7195
CVE-2015-7195
Description
The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.mozilla.org/security/announce/2015/mfsa2015-129.htmlnvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2015-11/msg00015.htmlnvd
- www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlnvd
- www.securitytracker.com/id/1034069nvd
- www.ubuntu.com/usn/USN-2785-1nvd
- bugzilla.mozilla.org/show_bug.cginvd
- security.gentoo.org/glsa/201512-10nvd
News mentions
0No linked articles in our index yet.