[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Clickjacking attack vulnerability in Mozilla Firefox since download "open file" dialog delay is too quick (Mac OS X)

ID: oval:org.secpod.oval:def:32854Date: (C)2016-02-09   (M)2023-11-19
Class: VULNERABILITYFamily: macos




The host is installed with Mozilla Firefox before 44.0 and is prone to a clickjacking attack vulnerability. A flaw is present in the application, which fails to properly handle delay between the download dialog getting focus and the button getting enabled was too short. Successful exploitation could lead unintentional actions such as the running of downloaded software.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS 11
Apple Mac OS X 10.15
Apple Mac OS X 10.14
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.9
Apple Mac OS X 10.10
Apple Mac OS X 10.11
Apple Mac OS X Server 10.9
Apple Mac OS X Server 10.10
Apple Mac OS X Server 10.11
Product:
Mozilla Firefox
Reference:
CVE-2016-1941
CVE    1
CVE-2016-1941

© SecPod Technologies