Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9902

Опубликовано: 14 дек. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 4.3
EPSS Низкий

Описание

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1404359Mozilla: Pocket extension does not validate the origin of events (MFSA 2016-94, MFSA 2016-95)

EPSS

Процентиль: 61%
0.00411
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
nvd
около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS3: 7.5
debian
около 7 лет назад

The Pocket toolbar button, once activated, listens for events fired fr ...

CVSS3: 7.5
github
больше 3 лет назад

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

oracle-oval
больше 8 лет назад

ELSA-2016-2973: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 61%
0.00411
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2