Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-9902
Description:The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-9902
BugTraq ID: 94885
http://www.securityfocus.com/bid/94885
https://security.gentoo.org/glsa/201701-15
RedHat Security Advisories: RHSA-2016:2946
http://rhn.redhat.com/errata/RHSA-2016-2946.html
RedHat Security Advisories: RHSA-2016:2973
http://rhn.redhat.com/errata/RHSA-2016-2973.html
http://www.securitytracker.com/id/1037461




© 1998-2025 E-Soft Inc. All rights reserved.