[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

iFrame sandbox bypass vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird - CVE-2020-15653

ID: oval:org.secpod.oval:def:64713Date: (C)2020-07-29   (M)2024-03-27
Class: VULNERABILITYFamily: windows




Mozilla Firefox 79, Mozilla Firefox ESR 78.1 and Mozilla Thunderbird 78.1: Mozilla developer Anne van Kesteren discovered that iframe sandbox with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content.

Platform:
Microsoft Windows Server 2022
Microsoft Windows 11
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows 10
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2016
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2019
Product:
Mozilla Firefox
Mozilla Firefox ESR
Mozilla Thunderbird
Reference:
CVE-2020-15653
CVE    1
CVE-2020-15653

© SecPod Technologies