CVE-2016-5291: Input Validation
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9066
- CVE-2016-5291
- CVE-2016-9074
- CVE-2016-5290
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
Frequently Asked Questions
What is CVE-2016-5291?
CVE-2016-5291 is a vulnerability that allows a same-origin policy bypass with local shortcut files to load arbitrary local content from disk.
Which software is affected by CVE-2016-5291?
CVE-2016-5291 affects Mozilla Thunderbird version up to 45.5, Mozilla Firefox version up to 50, and Mozilla Firefox ESR version up to 45.5.
What is the severity of CVE-2016-5291?
CVE-2016-5291 has a severity level of medium (4).
How can I fix CVE-2016-5291?
To fix CVE-2016-5291, update Mozilla Thunderbird to version 45.5, update Mozilla Firefox to version 50, or update Mozilla Firefox ESR to version 45.5.
Where can I find more information about CVE-2016-5291?
You can find more information about CVE-2016-5291 on the Mozilla Bugzilla website (https://bugzilla.mozilla.org/show_bug.cgi?id=1292159) and the Mozilla Security Advisories (https://www.mozilla.org/en-US/security/advisories/mfsa2016-93/ and https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/).