CVE Vulnerabilities

CVE-2016-9902

Origin Validation Error

Published: Jun 11, 2018 | Modified: Nov 25, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The Pocket toolbar button, once activated, listens for events fired from its own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Enterprise_linux_desktopRedhat5.0 (including)5.0 (including)
Enterprise_linux_desktopRedhat6.0 (including)6.0 (including)
Enterprise_linux_desktopRedhat7.0 (including)7.0 (including)
Enterprise_linux_serverRedhat5.0 (including)5.0 (including)
Enterprise_linux_serverRedhat6.0 (including)6.0 (including)
Enterprise_linux_serverRedhat7.0 (including)7.0 (including)
Enterprise_linux_server_ausRedhat7.3 (including)7.3 (including)
Enterprise_linux_server_ausRedhat7.4 (including)7.4 (including)
Enterprise_linux_server_eusRedhat7.3 (including)7.3 (including)
Enterprise_linux_server_eusRedhat7.4 (including)7.4 (including)
Enterprise_linux_server_eusRedhat7.5 (including)7.5 (including)
Enterprise_linux_workstationRedhat5.0 (including)5.0 (including)
Enterprise_linux_workstationRedhat6.0 (including)6.0 (including)
Enterprise_linux_workstationRedhat7.0 (including)7.0 (including)
Red Hat Enterprise Linux 5RedHatfirefox-0:45.6.0-1.el5_11*
Red Hat Enterprise Linux 5RedHatthunderbird-0:45.6.0-1.el5_11*
Red Hat Enterprise Linux 6RedHatfirefox-0:45.6.0-1.el6_8*
Red Hat Enterprise Linux 6RedHatthunderbird-0:45.6.0-1.el6_8*
Red Hat Enterprise Linux 7RedHatfirefox-0:45.6.0-1.el7_3*
Red Hat Enterprise Linux 7RedHatthunderbird-0:45.6.0-1.el7_3*
FirefoxUbuntudevel*
FirefoxUbuntuprecise*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuxenial*
FirefoxUbuntuyakkety*

References