CVE-2016-9071 — Mozilla Firefox vulnerability
Severity
5.3MEDIUMNVD
OSV9.8
EPSS
0.3%
top 50.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
3GHSA▶
GHSA-p26w-gphp-32x2: Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's brow↗2022-05-14
OSV▶
CVE-2016-9071: Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's brow↗2016-11-17
📋Vendor Advisories
3💬Community
1Bugzilla
▶