CVE-2016-2831: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only; version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • Mozilla Firefox: version 45.1.0 only; version 45.1.1 only; up to and including 46.0.1
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2016-06-13. Last modified 2026-06-17.