CVE-2016-2833Cross-site Scripting in Firefox

Severity
6.1MEDIUMNVD
OSV8.8
EPSS
0.3%
top 50.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

Ubuntumozilla/firefox< 47.0+build3-0ubuntu0.14.04.1+1
NVDmozilla/firefox46.0.1
debiandebian/firefox< firefox 47.0-1 (sid)
debiandebian/firefox-esr< firefox 47.0-1 (sid)
NVDopensuse/leap42.1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

🔴Vulnerability Details

3
GHSA
GHSA-w7mj-jcq9-3g34: Mozilla Firefox before 472022-05-14
OSV
firefox vulnerabilities2016-06-09
OSV
CVE-2016-2833: Mozilla Firefox before 472016-06-08

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-06-09
Red Hat
Mozilla: Java applets bypass CSP protections (MFSA 2016-60)2016-06-07
Debian
CVE-2016-2833: firefox - Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for...2016

💬Community

1
Bugzilla
CVE-2016-2833 Mozilla: Java applets bypass CSP protections (MFSA 2016-60)2016-06-06