CVE-2016-9064 describes a vulnerability in Firefox ESR < 45.5 and Firefox < 50 where add-on updates failed to verify the add-on ID within a signed package. This allowed a man-in-the-middle attacker, capable of defeating certificate pinning, to deliver a malicious signed add-on instead of a legitimate update. The CVSSv3 score of 5.9 (Medium) indicates a network-based attack with high impact to integrity, but requiring high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one media article mentioning its fix in Firefox 50.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 45.5.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 50.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.