Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rafael Gieschke

#20533of 53,633
12.4Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2016-6339
4.3
2016-09-20
Mozilla · Firefox · CVE-2016-5279
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 49.0 **Description** The issue allows remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code. This can be achieved when a user is tricked into performing a specific action, such as dragging and dropping a file. **Recommendations** For versions prior to 49.0, update to version 49.0 or later to resolve the issue.
PT-2016-2520
8.1
2016-08-02
Mozilla · Firefox · CVE-2016-5266
**Name of the Vulnerable Software and Affected Versions** Mozilla Firefox versions prior to 48.0 **Description** The issue is related to improper restriction of drag-and-drop operations for file: URL objects, which can be exploited by a remote attacker using a specially crafted website to access local files. This can allow user-assisted remote attackers to obtain access to local files. **Recommendations** For versions prior to 48.0, update to version 48.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of drag-and-drop functionality in Firefox until a patch is applied.