漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox、Firefox ESR和Thunderbird 安全漏洞
Vulnerability Description
Mozilla Firefox、Firefox ESR和Thunderbird都是由美国Mozilla基金会开发的产品。Firefox是一款开源Web浏览器,Firefox ESR是Firefox的一个延长支持版本。Thunderbird是从Mozilla Application Suite中独立出来的一套电子邮件客户端软件。 Mozilla Thunderbird 52.4之前的版本、Firefox ESR 52.4之前的版本和Firefox 56之前的版本中存在安全漏洞。远程攻击者可利用该漏洞实施跨站
CVSS Information
N/A
Vulnerability Type
N/A