Total vulnerabilities in the database
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.
Software | From | Fixed in |
---|---|---|
oracle / linux | 5.0 | 5.0.x |
oracle / linux | 6 | 6.x |
oracle / linux | 7 | 7.x |
mozilla / firefox | - | 47.0.1.x |
mozilla / firefox_esr | 45.1.1 | 45.1.1.x |
mozilla / firefox_esr | 45.1.0 | 45.1.0.x |
mozilla / firefox_esr | 45.2.0 | 45.2.0.x |
mozilla / firefox_esr | 45.3.0 | 45.3.0.x |