Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1696

Опубликовано: 26 июн. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4

Описание

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

РелизСтатусПримечание
devel

not-affected

23.0~b2+build1-0ubuntu1
lucid

ignored

end of life
precise

released

22.0+build1-0ubuntu0.12.04.1
quantal

released

22.0+build1-0ubuntu0.12.10.1
raring

released

22.0+build1-0ubuntu0.13.04.1
upstream

released

22.0

Показывать по

EPSS

Процентиль: 62%
0.00432
Низкий

4 Medium

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

nvd
больше 12 лет назад

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

debian
больше 12 лет назад

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Opti ...

github
больше 3 лет назад

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

EPSS

Процентиль: 62%
0.00432
Низкий

4 Medium

CVSS2