allow-scripts
, and subsequently appended an element to the iframe\'s document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe\'s sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
▸ CVE-2024-9999 ◂ Discovered: 12/11/2024 Status: PUBLISHED |
▸ CVE-2024-9997 ◂ Discovered: 29/10/2024 Status: PUBLISHED |
▸ CVE-2024-9996 ◂ Discovered: 29/10/2024 Status: PUBLISHED |
Tags:
CVE-2022-22759 Vulnerability Details