Oval Definition:oval:org.cisecurity:def:1793
Revision Date:2017-03-03Version:8
Title:XSS injection vulnerability in add-ons SDK - CVE-2016-9903
Description:Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2016-9903
Platform(s):Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows 8.1
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Mozilla Firefox
Definition Synopsis
  • Mozilla Firefox Mainline release is installed
  • AND Check if Mozilla Firefox Mainline version less than 50.1.0
  • BACK