vulnerability

MFSA2016-45 Firefox: CSP not applied to pages sent with multipart/x-mixed-replace (CVE-2016-2816)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Apr 26, 2016
Added
Apr 27, 2016
Modified
Aug 11, 2025

Description

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.

Solution

mozilla-firefox-upgrade-46_0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.