|
|
| |
|
| |
mozilla: cross-site scripting
| Package(s): | iceape, thunderbird, seamonkey, firefox |
CVE #(s): | CVE-2013-0751
|
| Created: | January 15, 2013 |
Updated: | February 18, 2013 |
| Description: |
From the CVE entry:
Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attackers to obtain sensitive information or possibly conduct cross-site scripting (XSS) attacks via a crafted HTML document. |
| Alerts: |
|
( Log in to post comments)
|
|
|