CVE-2016-9902

high

Description

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

References

https://www.mozilla.org/security/advisories/mfsa2016-95/

https://www.mozilla.org/security/advisories/mfsa2016-94/

https://security.gentoo.org/glsa/201701-15

http://www.securitytracker.com/id/1037461

http://www.securityfocus.com/bid/94885

http://rhn.redhat.com/errata/RHSA-2016-2973.html

http://rhn.redhat.com/errata/RHSA-2016-2946.html

Details

Source: Mitre, NVD

Published: 2018-06-11

Updated: 2018-08-09

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High