CVE-2016-9077 — Race Condition in Mozilla Firefox
Severity
7.0HIGHNVD
OSV9.8
EPSS
0.2%
top 61.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.
CVSS vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9
Affected Packages5 packages
🔴Vulnerability Details
3📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2016-9077 Mozilla: Canvas filters allow feDisplacementMaps to be applied to cross-origin images, allowing timing attacks on them (MFSA 2016-89)↗2016-11-15