Description
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-6234 | Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized. |
Ubuntu USN |
USN-3076-1 | Firefox vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-06T00:53:49.004Z
Reserved: 2016-06-03T00:00:00.000Z
Link: CVE-2016-5283
No data.
Status : Modified
Published: 2016-09-22T22:59:18.007
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-5283
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN