CVE-2016-1955 PUBLISHED

Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

EPSS 0.55% · 67.8th percentile

Risk Scores

EPSS Score
0.55%
67.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSfirefox0, 24.0+build1-0ubuntu1, 25.0+build3-0ubuntu0.13.10.1

Timeline

References

Open in Interactive Console →