Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-1949
Description:Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
Test IDs: 1.3.6.1.4.1.25623.1.2.1.2016.13   1.3.6.1.4.1.25623.1.0.807068   1.3.6.1.4.1.25623.1.0.807069   1.3.6.1.4.1.25623.1.0.842637  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-1949
https://security.gentoo.org/glsa/201605-06
http://www.securitytracker.com/id/1035007
SuSE Security Announcement: openSUSE-SU-2016:0489 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-02/msg00102.html
SuSE Security Announcement: openSUSE-SU-2016:0553 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-02/msg00142.html
http://www.ubuntu.com/usn/USN-2893-1




© 1998-2025 E-Soft Inc. All rights reserved.