Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1955

Опубликовано: 13 мар. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 4.3

Описание

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

РелизСтатусПримечание
devel

not-affected

45.0+build2-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [45.0+build2-0ubuntu0.14.04.1]]
precise

released

45.0+build2-0ubuntu0.12.04.1
trusty

released

45.0+build2-0ubuntu0.14.04.1
trusty/esm

DNE

trusty was released [45.0+build2-0ubuntu0.14.04.1]
upstream

released

45.0
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

released

45.0+build2-0ubuntu0.15.10.1
xenial

not-affected

45.0+build2-0ubuntu1

Показывать по

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
precise

not-affected

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

not-affected

vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

not-affected

xenial

not-affected

Показывать по

EPSS

Процентиль: 67%
0.00549
Низкий

4.3 Medium

CVSS2

4.3 Medium

CVSS3

Связанные уязвимости

redhat
почти 10 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

CVSS3: 4.3
nvd
почти 10 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

CVSS3: 4.3
debian
почти 10 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same ...

CVSS3: 4.3
github
больше 3 лет назад

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

fstec
почти 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю получить конфиденциальную информацию или обойти существующую политику ограничения доступа

EPSS

Процентиль: 67%
0.00549
Низкий

4.3 Medium

CVSS2

4.3 Medium

CVSS3