PT-2016-7875 · Mozilla+3 · Firefox+3

Kris Maglione

·

Publicado

2016-12-13

·

Atualizado

2024-12-12

·

CVE-2016-9903

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 50.1
Description A world-accessible resource in Mozilla's add-ons SDK contains an HTML injection issue. If another vulnerability allows this resource to be loaded as a document, it could enable injecting content and script into an add-on's context.
Recommendations For versions prior to 50.1, update to version 50.1 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2446
ALT-PU-2017-1578
CVE-2016-9903
MGASA-2017-0323
OPENSUSE-SU-2016_3184-1
OPENSUSE-SU-2016_3310-1
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
USN-3155-1

Produtos afetados

Alt Linux
Firefox
Suse
Ubuntu