Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2831

Опубликовано: 09 июн. 2016
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5thunderbirdNot affected
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 5firefoxFixedRHSA-2016:121708.06.2016
Red Hat Enterprise Linux 6firefoxFixedRHSA-2016:121708.06.2016
Red Hat Enterprise Linux 7firefoxFixedRHSA-2016:121708.06.2016

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1342898Mozilla: Entering fullscreen and persistent pointerlock without user permission (MFSA 2016-58)

EPSS

Процентиль: 73%
0.00775
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 9 лет назад

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

CVSS3: 8.8
nvd
около 9 лет назад

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

CVSS3: 8.8
debian
около 9 лет назад

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not en ...

CVSS3: 8.8
github
около 3 лет назад

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

fstec
около 9 лет назад

Уязвимость браузеров Firefox ESR и Firefox, позволяющая нарушителю вызвать отказ в обслуживании, провести кликджекинг или спуфинг-атаку

EPSS

Процентиль: 73%
0.00775
Низкий

4.3 Medium

CVSS2