CVE-2016-9077 describes a timing attack vulnerability in Firefox versions prior to 50, where the Canvas element's "feDisplacementMap" filter could be used on cross-origin images. This allowed for pixel-dependent rendering variations, enabling attackers to infer information about third-party images. Rated as High severity (CVSS 7.0), this vulnerability could lead to high confidentiality, integrity, and availability impacts through a local attack requiring user interaction and high attack complexity. There is no evidence of active exploitation, nor are there known public exploit modules or significant community discussion, despite some media coverage at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 50.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 50CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.