Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1955

Опубликовано: 13 мар. 2016
Источник: debian

Описание

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
iceweaselremovedpackage
iceweaselnot-affectedjessiepackage
iceweaselnot-affectedwheezypackage
firefox-esrfixed45.0esr-1package
firefoxfixed45.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-18/

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 10 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

redhat
больше 10 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

CVSS3: 4.3
nvd
больше 10 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

CVSS3: 4.3
github
больше 4 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

fstec
больше 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю получить конфиденциальную информацию или обойти существующую политику ограничения доступа