Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Canonical | 12.04 | 12.04 |
Ubuntu_linux | Canonical | 16.04 | 16.04 |
Ubuntu_linux | Canonical | 15.10 | 15.10 |
Ubuntu_linux | Canonical | 14.04 | 14.04 |