CVE-2016-9072 describes a vulnerability in Firefox versions prior to 50 on 64-bit Windows installations where the sandbox for 64-bit NPAPI plugins is not enabled by default for newly created profiles. This oversight could allow an attacker to bypass a critical security control. With a CVSS v3 score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, potentially leading to high integrity impacts without requiring user interaction. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB. While there's limited community discussion and media coverage, its EPSS score suggests a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 50.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 50CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.