CVE-2016-9073Mozilla Firefox vulnerability

CWE-2648 documents7 sources
Severity
7.5HIGHNVD
OSV9.8
EPSS
0.8%
top 25.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 50.0-1 (sid)
CVEListV5mozilla/firefoxunspecified50
NVDmozilla/firefox< 50.0
debiandebian/firefox-esr< firefox 50.0-1 (sid)
Ubuntumozilla/firefox< 50.0+build2-0ubuntu0.14.04.2+1

🔴Vulnerability Details

3
GHSA
GHSA-874r-f6v2-m748: WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox2022-05-14
OSV
firefox vulnerabilities2016-11-19
OSV
CVE-2016-9073: WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox2016-11-18

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-11-19
Red Hat
firefox: windows.create schema doesn't specify "format": "relativeUrl"2016-11-15
Debian
CVE-2016-9073: firefox - WebExtensions can bypass security checks to load privileged URLs and potentially...2016

💬Community

1
Bugzilla
CVE-2016-9073 firefox: windows.create schema doesn't specify "format": "relativeUrl"2016-11-18