Mozilla SeaMonkey CVE-2013-1696 Weak Authentication Vulnerability
Description
Bugzilla developer Frdric Buclin reported that the X-Frame-Options header is ignored when server push is used in multi-part responses. This can lead to potential clickjacking on sites that use X-Frame-Options as a protection.
Affected Applications
SeaMonkey