Количество 7
Количество 7
GHSA-gvh4-3r7j-cv8q
Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
CVE-2016-1949
Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
CVE-2016-1949
Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
CVE-2016-1949
Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
CVE-2016-1949
Mozilla Firefox before 44.0.2 does not properly restrict the interacti ...
openSUSE-SU-2016:0489-1
Security update for MozillaFirefox
BDU:2016-00528
Уязвимость браузера Firefox, позволяющая нарушителю обойти существующую политику ограничения доступа
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-gvh4-3r7j-cv8q Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file. | CVSS3: 8.8 | 1% Низкий | почти 10 лет назад | |
CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file. | CVSS2: 6.8 | 1% Низкий | почти 10 лет назад | |
CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file. | CVSS3: 8.8 | 1% Низкий | почти 10 лет назад | |
CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interacti ... | CVSS3: 8.8 | 1% Низкий | почти 10 лет назад | |
openSUSE-SU-2016:0489-1 Security update for MozillaFirefox | 1% Низкий | почти 10 лет назад | ||
BDU:2016-00528 Уязвимость браузера Firefox, позволяющая нарушителю обойти существующую политику ограничения доступа | CVSS2: 6.8 | 1% Низкий | почти 10 лет назад |
Уязвимостей на страницу