CVE-2016-5265
05.08.2016, 01:59
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.
Vendor | Product | Version |
---|---|---|
oracle | linux | 5.0 |
mozilla | firefox | 𝑥 ≤ 47.0.1 |
mozilla | firefox | 45.1.0 |
mozilla | firefox | 45.1.1 |
mozilla | firefox | 45.2.0 |
mozilla | firefox | 45.3.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References