CVE-2016-1947: Canonical Ubuntu Linux
Medium severity, CVSS 4.7. EPSS: 1.9% chance of exploitation in the next 30 days.
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
- Mozilla Firefox: version 43.0 only; version 43.0.1 only; version 43.0.2 only; version 43.0.3 only; version 43.0.4 only
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
Published 2016-01-31. Last modified 2026-06-17.