mozilla: cross-site scripting
Package(s): | iceape, thunderbird, seamonkey, firefox | CVE #(s): | CVE-2013-0751 | ||||||||||||||||||||||||||||||||
Created: | January 15, 2013 | Updated: | February 18, 2013 | ||||||||||||||||||||||||||||||||
Description: | From the CVE entry:
Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attackers to obtain sensitive information or possibly conduct cross-site scripting (XSS) attacks via a crafted HTML document. | ||||||||||||||||||||||||||||||||||
Alerts: |
|