CVE-2016-9076Improper Input Validation in Mozilla Firefox

Severity
5.9MEDIUMNVD
OSV9.8
EPSS
0.5%
top 32.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

An issue where a "" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages5 packages

debiandebian/firefox< firefox 50.0-1 (sid)
CVEListV5mozilla/firefoxunspecified50
NVDmozilla/firefox< 50.0
debiandebian/firefox-esr< firefox 50.0-1 (sid)
Ubuntumozilla/firefox< 50.0+build2-0ubuntu0.14.04.2+1

🔴Vulnerability Details

3
GHSA
GHSA-rj4h-3hm7-277q: An issue where a "" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks2022-05-14
OSV
firefox vulnerabilities2016-11-19
OSV
CVE-2016-9076: An issue where a "" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks2016-11-17

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-11-19
Red Hat
firefox: select dropdown menu can be used for URL bar spoofing on e10s2016-11-15
Debian
CVE-2016-9076: firefox - An issue where a "<select>" dropdown menu can be used to cover location bar cont...2016

💬Community

1
Bugzilla
CVE-2016-9076 firefox: select dropdown menu can be used for URL bar spoofing on e10s2016-11-18