CVE-2016-9071Mozilla Firefox vulnerability

CWE-2548 documents7 sources
Severity
5.3MEDIUMNVD
OSV9.8
EPSS
0.3%
top 50.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

debiandebian/firefox< firefox 50.0-1 (sid)
CVEListV5mozilla/firefoxunspecified50
NVDmozilla/firefox< 50.0
debiandebian/firefox-esr< firefox 50.0-1 (sid)
Ubuntumozilla/firefox< 50.0+build2-0ubuntu0.14.04.2+1

🔴Vulnerability Details

3
GHSA
GHSA-p26w-gphp-32x2: Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's brow2022-05-14
OSV
firefox vulnerabilities2016-11-19
OSV
CVE-2016-9071: Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's brow2016-11-17

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-11-19
Red Hat
Mozilla: Probe browser history via HSTS/301 redirect + CSP (MFSA 2016-89)2016-11-15
Debian
CVE-2016-9071: firefox - Content Security Policy combined with HTTP to HTTPS redirection can be used by m...2016

💬Community

1
Bugzilla
CVE-2016-9071 Mozilla: Probe browser history via HSTS/301 redirect + CSP (MFSA 2016-89)2016-11-15