CVE-2016-9900
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
HIGH · CVSS 7.5
EPSS 0.01417
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0