[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-USN-3124-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":86,"duplicates":87,"related":88,"reserved_at":9,"published_at":107,"modified_at":108,"state":9,"summary":109,"references_raw":111,"kevs":191,"epss":9,"epss_history":192,"metrics":193,"affected":194},"USN-3124-1","firefox vulnerabilities\n\nChristian Holler, Andrew McCreight, Dan Minor, Tyson Smith, Jon Coppeard,\nJan-Ivar Bruaroey, Jesse Ruderman, Markus Stange, Olli Pettay, Ehsan\nAkhgari, Gary Kwong, Tooru Fujisawa, and Randell Jesup discovered multiple\nmemory safety issues in Firefox. If a user were tricked in to opening a\nspecially crafted website, an attacker could potentially exploit these to\ncause a denial of service via application crash, or execute arbitrary\ncode. (CVE-2016-5289, CVE-2016-5290)\n\nA same-origin policy bypass was discovered with local HTML files in some\ncircumstances. An attacker could potentially exploit this to obtain\nsensitive information. (CVE-2016-5291)\n\nA crash was discovered when parsing URLs in some circumstances. If a user\nwere tricked in to opening a specially crafted website, an attacker could\npotentially exploit this to execute arbitrary code. (CVE-2016-5292)\n\nA heap buffer-overflow was discovered in Cairo when processing SVG\ncontent. If a user were tricked in to opening a specially crafted website,\nan attacker could potentially exploit this to cause a denial of service\nvia application crash, or execute arbitrary code. (CVE-2016-5296)\n\nAn error was discovered in argument length checking in Javascript. If a\nuser were tricked in to opening a specially crafted website, an attacker\ncould potentially exploit this to cause a denial of service via\napplication crash, or execute arbitrary code. (CVE-2016-5297)\n\nAn integer overflow was discovered in the Expat library. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash. (CVE-2016-9063)\n\nIt was discovered that addon updates failed to verify that the addon ID\ninside the signed package matched the ID of the addon being updated.\nAn attacker that could perform a machine-in-the-middle (MITM) attack could\npotentially exploit this to provide malicious addon updates.\n(CVE-2016-9064)\n\nA buffer overflow was discovered in nsScriptLoadHandler. If a user were\ntricked in to opening a specially crafted website, an attacker could\npotentially exploit this to cause a denial of service via application\ncrash, or execute arbitrary code. (CVE-2016-9066)\n\n2 use-after-free bugs were discovered during DOM operations in some\ncircumstances. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit these to cause a denial of\nservice via application crash, or execute arbitrary code. (CVE-2016-9067,\nCVE-2016-9069)\n\nA heap use-after-free was discovered during web animations in some\ncircumstances. If a user were tricked in to opening a specially crafted\nwebsite, an attacker could potentially exploit this to cause a denial of\nservice via application crash, or execute arbitrary code. (CVE-2016-9068)\n\nIt was discovered that a page loaded in to the sidebar through a bookmark\ncould reference a privileged chrome window. An attacker could potentially\nexploit this to bypass same origin restrictions. (CVE-2016-9070)\n\nAn issue was discovered with Content Security Policy (CSP) in combination\nwith HTTP to HTTPS redirection. An attacker could potentially exploit this\nto verify whether a site is within the user's browsing history.\n(CVE-2016-9071)\n\nAn issue was discovered with the windows.create() WebExtensions API. If a\nuser were tricked in to installing a malicious extension, an attacker\ncould potentially exploit this to escape the WebExtensions sandbox.\n(CVE-2016-9073)\n\nIt was discovered that WebExtensions can use the mozAddonManager API. An\nattacker could potentially exploit this to install additional extensions\nwithout user permission. (CVE-2016-9075)\n\nIt was discovered that \u003Cselect> element dropdown menus can cover location\nbar content when e10s is enabled. An attacker could potentially exploit\nthis to conduct UI spoofing attacks. (CVE-2016-9076)\n\nIt was discovered that canvas allows the use of the feDisplacementMap\nfilter on cross-origin images. An attacker could potentially exploit this\nto conduct timing attacks. (CVE-2016-9077)\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84],{"_key":15},"CVE-2016-5289",{"_key":17},"CVE-2016-5290",{"_key":19},"CVE-2016-5291",{"_key":21},"CVE-2016-5292",{"_key":23},"CVE-2016-5296",{"_key":25},"CVE-2016-5297",{"_key":27},"CVE-2016-9063",{"_key":29},"CVE-2016-9064",{"_key":31},"CVE-2016-9066",{"_key":33},"CVE-2016-9067",{"_key":35},"CVE-2016-9068",{"_key":37},"CVE-2016-9069",{"_key":39},"CVE-2016-9070",{"_key":41},"CVE-2016-9071",{"_key":43},"CVE-2016-9073",{"_key":45},"CVE-2016-9075",{"_key":47},"CVE-2016-9076",{"_key":49},"CVE-2016-9077",{"_key":51},"UBUNTU-CVE-2016-5289",{"_key":53},"UBUNTU-CVE-2016-5290",{"_key":55},"UBUNTU-CVE-2016-5291",{"_key":57},"UBUNTU-CVE-2016-5292",{"_key":59},"UBUNTU-CVE-2016-5296",{"_key":61},"UBUNTU-CVE-2016-5297",{"_key":63},"UBUNTU-CVE-2016-9063",{"_key":65},"UBUNTU-CVE-2016-9064",{"_key":67},"UBUNTU-CVE-2016-9066",{"_key":69},"UBUNTU-CVE-2016-9067",{"_key":71},"UBUNTU-CVE-2016-9068",{"_key":73},"UBUNTU-CVE-2016-9069",{"_key":75},"UBUNTU-CVE-2016-9070",{"_key":77},"UBUNTU-CVE-2016-9071",{"_key":79},"UBUNTU-CVE-2016-9073",{"_key":81},"UBUNTU-CVE-2016-9075",{"_key":83},"UBUNTU-CVE-2016-9076",{"_key":85},"UBUNTU-CVE-2016-9077",[],[],[89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106],{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},{"_key":69},{"_key":71},{"_key":73},{"_key":75},{"_key":77},{"_key":79},{"_key":81},{"_key":83},{"_key":85},"2016-11-19T00:07:46Z","2026-04-22T09:29:43.804199Z",{"cisa_kev":110,"cisa_ransomware":110,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[112,118,123,127,131,135,139,143,147,151,155,159,163,167,171,175,179,183,187],{"url":113,"sources":114,"tags":116},"https://ubuntu.com/security/notices/USN-3124-1",[115],"osv_ubuntu",[117],"Advisory",{"url":119,"sources":120,"tags":121},"https://ubuntu.com/security/CVE-2016-5289",[115],[122],"REPORT",{"url":124,"sources":125,"tags":126},"https://ubuntu.com/security/CVE-2016-5290",[115],[122],{"url":128,"sources":129,"tags":130},"https://ubuntu.com/security/CVE-2016-5291",[115],[122],{"url":132,"sources":133,"tags":134},"https://ubuntu.com/security/CVE-2016-5292",[115],[122],{"url":136,"sources":137,"tags":138},"https://ubuntu.com/security/CVE-2016-5296",[115],[122],{"url":140,"sources":141,"tags":142},"https://ubuntu.com/security/CVE-2016-5297",[115],[122],{"url":144,"sources":145,"tags":146},"https://ubuntu.com/security/CVE-2016-9063",[115],[122],{"url":148,"sources":149,"tags":150},"https://ubuntu.com/security/CVE-2016-9064",[115],[122],{"url":152,"sources":153,"tags":154},"https://ubuntu.com/security/CVE-2016-9066",[115],[122],{"url":156,"sources":157,"tags":158},"https://ubuntu.com/security/CVE-2016-9067",[115],[122],{"url":160,"sources":161,"tags":162},"https://ubuntu.com/security/CVE-2016-9068",[115],[122],{"url":164,"sources":165,"tags":166},"https://ubuntu.com/security/CVE-2016-9069",[115],[122],{"url":168,"sources":169,"tags":170},"https://ubuntu.com/security/CVE-2016-9070",[115],[122],{"url":172,"sources":173,"tags":174},"https://ubuntu.com/security/CVE-2016-9071",[115],[122],{"url":176,"sources":177,"tags":178},"https://ubuntu.com/security/CVE-2016-9073",[115],[122],{"url":180,"sources":181,"tags":182},"https://ubuntu.com/security/CVE-2016-9075",[115],[122],{"url":184,"sources":185,"tags":186},"https://ubuntu.com/security/CVE-2016-9076",[115],[122],{"url":188,"sources":189,"tags":190},"https://ubuntu.com/security/CVE-2016-9077",[115],[122],[],[],[],[195],{"ecosystem":196,"name":197,"vendor":198,"product":197,"cpe_part":9,"purl_type":199,"purl_namespace":198,"purl_name":197,"source":9,"versions":200},"Ubuntu","firefox","ubuntu","deb",[201,207],{"version":202,"is_range":203,"range_type":204,"version_start":9,"version_start_type":9,"version_end":205,"version_end_type":206,"fixed_in":9},"lt50_0+build2_0ubuntu0_14_04_2",true,"ecosystem","50.0+build2-0ubuntu0.14.04.2","excluding",{"version":208,"is_range":203,"range_type":204,"version_start":9,"version_start_type":9,"version_end":209,"version_end_type":206,"fixed_in":9},"lt50_0+build2_0ubuntu0_16_04_2","50.0+build2-0ubuntu0.16.04.2"]