Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade firefox-esr | Jul 30, 2024 | Mar 13, 2016 |
| Freebsd | — | Upgrade firefoxUpgrade linux-seamonkeyUpgrade firefox-esrUpgrade seamonkeyUpgrade thunderbirdUpgrade linux-thunderbirdUpgrade linux-firefoxUpgrade libxul | Dec 10, 2025 | Mar 8, 2016 |
| Gentoo Linux | — | Upgrade www-client/firefox.Upgrade dev-libs/nss.Upgrade dev-libs/nspr.Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird.Upgrade www-client/firefox-bin. | Oct 30, 2017 | Mar 13, 2016 |
| Mfsa2016 18 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 45.0 | Mar 10, 2016 | Mar 8, 2016 |
| Mozilla Thunderbird | — | Upgrade to the latest version of Mozilla ThunderbirdUpgrade to Mozilla Thunderbird version 45.0 | Apr 15, 2016 | Mar 13, 2016 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 45.3.0-0.175.3.14.0.4.0 on Solaris 11.3Upgrade developer/yasm to version 1.3.0-0.175.3.14.0.2.0 on Solaris 11.3 | May 29, 2017 | Mar 13, 2016 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaThunderbird-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-translations-otherUpgrade MozillaThunderbird-buildsymbolsUpgrade MozillaFirefox-develUpgrade MozillaThunderbirdUpgrade MozillaThunderbird-develUpgrade MozillaThunderbird-translations-common | Mar 14, 2016 | Mar 12, 2016 |
| Ubuntu | — | Upgrade firefox | Mar 13, 2016 | Mar 13, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub