JSON View XML View

Key Value
MTID M116524
Title Mozilla Firefox /FireFox ESR CSP Security Bypass
Description A vulnerability in some versions of Mozilla Firefox /Firefox ESR could lead to a security bypass.
Observation A vulnerability in some versions of Mozilla Firefox /Firefox ESR could lead to a security bypass.

The flaw occurs when event handlers on marquee elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. Successful exploitation could allow a remote attacker to bypass intended access restrictions.
Recommendation The vendor has released an update to address the issue:

https://www.mozilla.org/en-US/security/advisories/mfsa2016-94/
https://www.mozilla.org/en-US/security/advisories/mfsa2016-95/

Vendor Mozilla
Attack Vector Undetermined
Importance 5
Impact 10.00084536000
Threat Score 9.33
Labels
References
CVECVE-2016-9895
MTIDM116524
CPEs
cpe:/a:mozilla:firefox_esr:45.5
cpe:/a:mozilla:firefox:50.0.2
Created At 2016-12-13 00:00:00 UTC
Updated At 2016-12-16 10:31:08 UTC

Back