Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox Add-on SDK 安全漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 42.0.2及之前版本的Add-on SDK中存在安全漏洞,该漏洞源于程序没有正确处理‘script: false’面板设置。远程攻击者可借助在第三方扩展中使用的内联JavaScript代码利用该漏洞实施跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A