CVE-2016-9901

Severity
9.8CRITICAL
EPSS
2.0%
top 16.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages8 packages

CVEListV5mozilla/firefoxunspecified50.1
NVDmozilla/firefox< 45.6.0+1
CVEListV5mozilla/firefox_esrunspecified45.6
Ubuntufirefox< 50.1.0+build2-0ubuntu0.14.04.1+1
Debianfirefox-esr< 45.6.0esr-1+3

Also affects: Enterprise Linux 7.3, 7.4, 7.5

Patches

🔴Vulnerability Details

4
GHSA
GHSA-6g72-x2jp-6592: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sav2022-05-14
CVEList
CVE-2016-9901: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sav2018-06-11
OSV
CVE-2016-9901: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-sav2018-06-11
OSV
firefox vulnerabilities2016-12-13

📋Vendor Advisories

3
Red Hat
Mozilla: Data from Pocket server improperly sanitized before execution (MFSA 2016-94, MFSA 2016-95)2016-12-14
Ubuntu
Firefox vulnerabilities2016-12-13
Debian
CVE-2016-9901: firefox - HTML tags received from the Pocket server will be processed without sanitization...2016

💬Community

1
Bugzilla
CVE-2016-9901 Mozilla: Data from Pocket server improperly sanitized before execution (MFSA 2016-94, MFSA 2016-95)2016-12-13
CVE-2016-9901 (CRITICAL CVSS 9.8) | HTML tags received from the Pocket | cvebase.io