6.1
CVE-2016-9895
- EPSS 1.84%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 25.11.2025 17:50:16
- Erkennungen
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Enterprise Linux Version 5.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 5.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 5.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.3
Redhat ≫ Enterprise Linux Server Aus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.3
Redhat ≫ Enterprise Linux Server Eus Version 7.4
Redhat ≫ Enterprise Linux Server Eus Version 7.5
Redhat ≫ Enterprise Linux Workstation Version 5.0
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Mozilla ≫ Thunderbird Version < 45.6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.84% | 0.762 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
https://security.gentoo.org/glsa/201701-15
http://www.securitytracker.com/id/1037461
https://www.mozilla.org/security/advisories/mfsa2016-94/
http://rhn.redhat.com/errata/RHSA-2016-2946.html
http://rhn.redhat.com/errata/RHSA-2016-2973.html
http://www.securityfocus.com/bid/94885
https://www.debian.org/security/2017/dsa-3757
https://www.mozilla.org/security/advisories/mfsa2016-95/
https://www.mozilla.org/security/advisories/mfsa2016-96/
https://bugzilla.mozilla.org/show_bug.cgi?id=1312272