← back
CVE-2016-9900

CVE-2016-9900

EPSS 9.9%
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →