Oval Definition:oval:org.cisecurity:def:1787
Revision Date:2017-03-03Version:8
Title:Cross-origin information leak in shared atoms - CVE-2016-9905
Description:An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2016-9905
MFSA2016-95
Platform(s):Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox ESR
Definition Synopsis
  • Mozilla Firefox ESR release is installed + version
  • Mozilla Firefox ESR is installed
  • AND Check if Mozilla Firefox ESR version less than 45.6.0
  • BACK