Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esr | Jul 30, 2024 | Feb 13, 2016 |
| Freebsd | — | Upgrade linux-firefoxUpgrade firefox | Dec 10, 2025 | Feb 15, 2016 |
| Gentoo Linux | — | Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade www-client/firefox.Upgrade mail-client/thunderbird.Upgrade dev-libs/nspr.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Feb 12, 2016 |
| Mfsa2016 13 | — | Upgrade to Mozilla Firefox version 44.0.2 | Feb 12, 2016 | Feb 11, 2016 |
| Suse | — | Upgrade mozillafirefox-translations-commonUpgrade mozillafirefox-develUpgrade mozillafirefoxUpgrade mozillafirefox-translations-other | Feb 17, 2016 | Feb 12, 2016 |
| Ubuntu | — | Upgrade firefox | Feb 12, 2016 | Feb 11, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub