CVE-2016-9078 describes a vulnerability in Firefox versions 49 and 50 where redirecting from an HTTP connection to a "data:" URL could assign the referring site's origin to the "data:" URL, leading to same-origin policy violations. This high-severity flaw (CVSS 8.8) allows for cross-origin cookie setting and has a potential for high impact on confidentiality, integrity, and availability, requiring user interaction to exploit. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it garnered significant community discussion and media coverage, including mentions in relation to the "Disdain" Exploit Kit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
49.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:49.0:*:*:*:*:*:*:* | ||
50.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:50.0:*:*:*:*:*:*:* | ||
< 50.0.1CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.