Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox和Firefox ESR 安全漏洞
Vulnerability Description
Mozilla Firefox和Firefox ESR都是美国Mozilla基金会开发的浏览器产品。Firefox是一款开源Web浏览器;Firefox ESR是Firefox的一个延长支持版本。 Mozilla Firefox 40.0.3之前版本和Firefox ESR 38.2.1之前38.x版本的add-on installation功能中存在安全漏洞。远程攻击者可通过构建特制的data: URL,并在安装进程初期将其导航到任意http:或https: URL,利用该漏洞绕过既定的user-con
CVSS Information
N/A
Vulnerability Type
N/A