Логотип exploitDog
bind:"CVE-2016-2817"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2016-2817"

Количество 7

Количество 7

ubuntu логотип

CVE-2016-2817

почти 10 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2016-2817

почти 10 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-2817

почти 10 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2016-2817

почти 10 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext- ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-px89-65ch-24x4

больше 3 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2016-01148

почти 10 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю проводить UXSS-атаки

CVSS2: 4.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:1211-1

почти 10 лет назад

Security update update for MozillaFirefox, mozilla-nss

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
0%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS2: 4.3
0%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
0%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext- ...

CVSS3: 5.4
0%
Низкий
почти 10 лет назад
github логотип
GHSA-px89-65ch-24x4

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2016-01148

Уязвимость браузера Firefox, позволяющая нарушителю проводить UXSS-атаки

CVSS2: 4.3
0%
Низкий
почти 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:1211-1

Security update update for MozillaFirefox, mozilla-nss

почти 10 лет назад

Уязвимостей на страницу