Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Leap | Opensuse | 42.1 | 42.1 |
Opensuse | Opensuse | 13.1 | 13.1 |
Opensuse | Opensuse | 13.2 | 13.2 |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | esm-infra/xenial | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | trusty | * |
Firefox | Ubuntu | upstream | * |
Firefox | Ubuntu | wily | * |
Firefox | Ubuntu | xenial | * |