CVE-2016-9900Sensitive Information Exposure in Mozilla Firefox

Severity
7.5HIGHNVD
OSV9.8
EPSS
1.0%
top 22.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages10 packages

CVEListV5mozilla/firefoxunspecified50.1
NVDmozilla/firefox< 50.1+1
CVEListV5mozilla/firefox_esrunspecified45.6
Ubuntumozilla/firefox< 50.1.0+build2-0ubuntu0.14.04.1+1
CVEListV5mozilla/thunderbirdunspecified45.6

Also affects: Debian Linux 9.0, Enterprise Linux 5.0, 6.0, 7.0, 7.3, 7.4, 7.5

Patches

🔴Vulnerability Details

5
GHSA
GHSA-5758-qh2j-cmj3: External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs2022-05-14
OSV
CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs2018-06-11
CVEList
CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs2018-06-11
OSV
thunderbird vulnerabilities2017-01-28
OSV
firefox vulnerabilities2016-12-13

📋Vendor Advisories

5
Red Hat
kernel: Info leak in uninitialized structure ethtool_wolinfo in ethtool_get_wol()2017-07-25
Ubuntu
Thunderbird vulnerabilities2017-01-28
Red Hat
Mozilla: Restricted external resources can be loaded by SVG images through data URLs (MFSA 2016-94, MFSA 2016-95)2016-12-14
Ubuntu
Firefox vulnerabilities2016-12-13
Debian
CVE-2016-9900: firefox - External resources that should be blocked when loaded by SVG images can bypass s...2016

💬Community

2
Bugzilla
CVE-2014-9900 kernel: Info leak in uninitialized structure ethtool_wolinfo in ethtool_get_wol()2017-08-14
Bugzilla
CVE-2016-9900 Mozilla: Restricted external resources can be loaded by SVG images through data URLs (MFSA 2016-94, MFSA 2016-95)2016-12-13
CVE-2016-9900 — Sensitive Information Exposure | cvebase