4
CVSSv2

CVE-2013-1696

Published: 26/06/2013 Updated: 19/09/2017
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

Mozilla Firefox prior to 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote malicious users to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox 19.0.1

mozilla firefox 19.0.2

mozilla firefox 20.0

mozilla firefox 20.0.1

mozilla firefox 19.0

mozilla firefox

Vendor Advisories

USN-1890-1 introduced a regression in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2013-58 X-Frame-Options ignored when using server push with multi-part responses Announced June 25, 2013 Reporter Frédéric Buclin Impact Moderate Products Firefox, SeaMonkey Fixed ...
Mozilla Firefox before 220 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses ...