First published: Sun Jan 31 2016(Updated: )
The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <=43.0.4 | |
openSUSE | =42.1 | |
openSUSE | =13.1 | |
openSUSE | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1937 has a moderate severity rating as it allows for clickjacking attacks.
To fix CVE-2016-1937, update Mozilla Firefox to version 44.0 or later.
CVE-2016-1937 affects Mozilla Firefox versions prior to 44.0.
Yes, CVE-2016-1937 can be exploited on affected versions of openSUSE including 42.1, 13.1, and 13.2.
CVE-2016-1937 is related to clickjacking attacks that enable remote attackers to manipulate user actions.