Security Advisory

CVE-2016-2833

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2016-06-13 10:00:00
Last updated 2024-08-05 23:32:21
Assigner mozilla
State PUBLISHED

Description

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.