CVE-2016-2833

Publication date

2016-06-13 10:00:00

Family

mozilla

State

PUBLISHED

Description

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.