CVE-2016-9900 — Sensitive Information Exposure in Mozilla Firefox
Severity
7.5HIGHNVD
OSV9.8
EPSS
1.0%
top 22.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages10 packages
Also affects: Debian Linux 9.0, Enterprise Linux 5.0, 6.0, 7.0, 7.3, 7.4, 7.5
Patches
🔴Vulnerability Details
5GHSA▶
GHSA-5758-qh2j-cmj3: External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs↗2022-05-14
OSV▶
CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs↗2018-06-11
CVEList▶
CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs↗2018-06-11