CVE-2016-9904Sensitive Information Exposure in Mozilla Firefox

Severity
7.5HIGHNVD
OSV9.8OSV7.8
EPSS
1.2%
top 21.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages13 packages

debiandebian/firefox< firefox 50.1.0-1 (sid)
CVEListV5mozilla/firefoxunspecified50.1
NVDmozilla/firefox< 45.6.0+1
debiandebian/firefox-esr< firefox 50.1.0-1 (sid)
CVEListV5mozilla/firefox_esrunspecified45.6

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

5
GHSA
GHSA-h92w-5p82-frc3: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts2022-05-14
OSV
CVE-2016-9904: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts2018-06-11
OSV
thunderbird vulnerabilities2017-01-28
OSV
firefox vulnerabilities2016-12-13
OSV
linux vulnerabilities2016-11-11

📋Vendor Advisories

4
Ubuntu
Thunderbird vulnerabilities2017-01-28
Red Hat
Mozilla: Cross-origin information leak in shared atoms (MFSA 2016-94, MFSA 2016-95)2016-12-14
Ubuntu
Firefox vulnerabilities2016-12-13
Debian
CVE-2016-9904: firefox - An attacker could use a JavaScript Map/Set timing attack to determine whether an...2016

💬Community

2
Bugzilla
CVE-2016-9904 Mozilla: Cross-origin information leak in shared atoms (MFSA 2016-94, MFSA 2016-95)2016-12-13
Bugzilla
CVE-2012-6703 kernel: Integer overflow in compress_core2016-06-29