CVE-2016-5283: High severity firefox vulnerability
A timing attack vulnerability using iframes to potentially reveal private data using document resizes and link colors.
Other sources
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
— Launchpad
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2016-5283?
CVE-2016-5283 is a timing attack vulnerability in Mozilla Firefox before version 49.0 that allows remote attackers to bypass the Same Origin Policy.
How does CVE-2016-5283 work?
CVE-2016-5283 works by using a crafted fragment identifier in the SRC attribute of an IFRAME element to bypass Same Origin Policy restrictions.
What is the severity of CVE-2016-5283?
The severity of CVE-2016-5283 is high, with a CVSS score of 8.8.
How can I fix CVE-2016-5283?
To fix CVE-2016-5283, update Mozilla Firefox to version 49.0 or later.
Where can I find more information about CVE-2016-5283?
More information about CVE-2016-5283 can be found in the following references: [link1], [link2], [link3]