CVE-2013-1696

Publication date

2013-06-26 01:00:00

Family

mozilla

State

PUBLISHED

Description

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.