CVE-2016-9078 PUBLISHED

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. This vulnerability affects Firefox < 50.0.1.

EPSS 1.18% · 78.6th percentile

Risk Scores

EPSS Score
1.18%
78.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSfirefox0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1
Ubuntu:14.04:LTSfirefox36.0+build2-0ubuntu0.14.04.4, 36.0.1+build2-0ubuntu0.14.04.1, 36.0.4+build1-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →