CVE-2016-9075: Critical severity firefox vulnerability
Published Nov 15, 2016
·Updated
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<50
50
Mozilla Firefox<50.0
Event History
Nov 15, 2016
CVE Published
12:00 AM
Jun 11, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2016-5296
- CVE-2016-5292
- CVE-2016-5293
- CVE-2016-5294
- CVE-2016-5297
- CVE-2016-9064
- CVE-2016-9065
- CVE-2016-9066
- CVE-2016-9067
- CVE-2016-9068
- CVE-2016-9072
- CVE-2016-9075
- CVE-2016-9077
- CVE-2016-5291
- CVE-2016-5295
- CVE-2016-5298
- CVE-2016-5299
- CVE-2016-9061
- CVE-2016-9062
- CVE-2016-9070
- CVE-2016-9073
- CVE-2016-9074
- CVE-2016-9076
- CVE-2016-9063
- CVE-2016-9071
- CVE-2016-5289
- CVE-2016-5290
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2016-9075.
2
What is the severity of CVE-2016-9075?
The severity of CVE-2016-9075 is critical with a CVSS score of 9.8.
3
How does CVE-2016-9075 affect Firefox?
CVE-2016-9075 affects Firefox versions before 50.0.
4
What is the impact of CVE-2016-9075?
CVE-2016-9075 allows a malicious extension to install additional extensions without explicit user permission.
5
Are there any references for CVE-2016-9075?
Yes, you can find references for CVE-2016-9075 at the following links: [1] [2] [3].