CVE-2015-7195: Mozilla Firefox
Medium severity, CVSS 5.0. EPSS: 2.2% chance of exploitation in the next 30 days.
The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect.
Affected products
- Mozilla Firefox: up to and including 41.0.2
Published 2015-11-05. Last modified 2026-06-17.