Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-0819

Опубликовано: 25 фев. 2015
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

РелизСтатусПримечание
devel

released

36.0+build2-0ubuntu4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [36.0+build2-0ubuntu0.14.04.4]]
lucid

ignored

end of life
precise

released

36.0+build2-0ubuntu0.12.04.5
trusty

released

36.0+build2-0ubuntu0.14.04.4
trusty/esm

DNE

trusty was released [36.0+build2-0ubuntu0.14.04.4]
upstream

released

36
utopic

released

36.0+build2-0ubuntu0.14.10.4

Показывать по

EPSS

Процентиль: 75%
0.00913
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
почти 11 лет назад

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

nvd
почти 11 лет назад

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

debian
почти 11 лет назад

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does n ...

github
больше 3 лет назад

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

EPSS

Процентиль: 75%
0.00913
Низкий

4.3 Medium

CVSS2