Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9902

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Низкий

Описание

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed50.1.0-1package
firefox-esrfixed45.6.0esr-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2016-95/#CVE-2016-9902

EPSS

Процентиль: 61%
0.00411
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
redhat
больше 8 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
nvd
около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
github
больше 3 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

oracle-oval
больше 8 лет назад

ELSA-2016-2973: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 61%
0.00411
Низкий