CVE-2016-2831: High severity ubuntu vulnerability
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2831?
CVE-2016-2831 has a moderate severity rating due to the potential for denial of service and clickjacking attacks.
How do I fix CVE-2016-2831?
To fix CVE-2016-2831, update Mozilla Firefox to version 47.0 or later, or Firefox ESR to version 45.2 or later.
What versions of Mozilla Firefox are affected by CVE-2016-2831?
CVE-2016-2831 affects Mozilla Firefox versions before 47.0 and Firefox ESR versions before 45.2.
Can CVE-2016-2831 be exploited on all operating systems?
Yes, CVE-2016-2831 can be exploited on any operating system that runs the affected versions of Mozilla Firefox.
What types of attacks can be executed due to CVE-2016-2831?
CVE-2016-2831 can enable denial of service, clickjacking, and spoofing attacks through malicious web content.