Security Advisory

CVE-2013-1696

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2013-06-26 01:00:00
Last updated 2024-08-06 15:13:32
Assigner mozilla
State PUBLISHED

Description

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.