CVE-2016-9895: Medium severity thunderbird vulnerability
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Other sources
Event handlers on marquee elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2016-9895?
CVE-2016-9895 is a moderate severity vulnerability affecting certain versions of Firefox, Firefox ESR, and Thunderbird.
Which versions are affected by CVE-2016-9895?
CVE-2016-9895 affects Firefox versions below 50.1, Firefox ESR versions below 45.6, and Thunderbird versions below 45.6.
How do I fix CVE-2016-9895?
To fix CVE-2016-9895, upgrade Firefox to version 50.1 or later, Firefox ESR to version 45.6 or later, or Thunderbird to version 45.6 or later.
Is there a workaround for CVE-2016-9895?
There is no documented workaround for CVE-2016-9895; updating to the latest versions is recommended.
What impact does CVE-2016-9895 have on users?
CVE-2016-9895 allows execution of event handlers on marquee elements despite a strict Content Security Policy, potentially leading to security risks.