CVE-2016-9903Cross-site Scripting in Mozilla Firefox

Severity
6.1MEDIUMNVD
OSV9.8
EPSS
0.7%
top 27.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5mozilla/firefoxunspecified50.1
NVDmozilla/firefox< 50.1
Ubuntumozilla/firefox< 50.1.0+build2-0ubuntu0.14.04.1+1
debiandebian/firefox< firefox 50.1.0-1 (sid)
debiandebian/firefox-esr< firefox 50.1.0-1 (sid)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9fhg-wr6f-g4x9: Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability2022-05-14
OSV
firefox vulnerabilities2016-12-13
OSV
CVE-2016-9903: Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability2016-12-13

📋Vendor Advisories

2
Ubuntu
Firefox vulnerabilities2016-12-13
Debian
CVE-2016-9903: firefox - Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vul...2016