Show filters
23 Total Results
Displaying 21-23 of 23
Sort by:
Attacker Value
Unknown
CVE-2016-5262
Disclosure Date: August 05, 2016 (last updated October 23, 2024)
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-2830
Disclosure Date: August 05, 2016 (last updated October 23, 2024)
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.
0
Attacker Value
Unknown
CVE-2016-5259
Disclosure Date: August 05, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.
0