Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability affects Firefox < 144 and Thunderbird < 144.
Publication date: Tue, 14 Oct 2025 12:27:00 +0000
Cyber News related to CVE-2025-11716
CVE-2025-11716 - Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability affects Firefox < 144 and Thunderbird < 144. ...
4 months ago
CVE-2017-11716 - MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode. ...
8 years ago
CVE-2018-11716 - An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled ...
7 years ago
CVE-2019-11716 - Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window ...
6 years ago
CVE-2020-11716 - Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support." ...
3 years ago
CVE-2024-11716 - While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a ...
1 year ago Tenable.com