ZeroHour

CVE-2016-2831

CVSS 3.0
8.8 high
EPSS
1%p70
Published
()
Modified
Description

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

Vendors
canonicalmozilladebianopensuse
Products
ubuntu linux, firefox, debian linux, leap, opensuse
Weakness
CWE-254, CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.