CVE-2016-9901: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Affected products

  • Mozilla Firefox: before 45.6.0 (fixed in 45.6.0); before 50.1 (fixed in 50.1)
  • Red Hat Enterprise Linux Aus: version 7.3 only; version 7.4 only
  • Red Hat Enterprise Linux Desktop: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Eus: version 7.3 only; version 7.4 only; version 7.5 only
  • Red Hat Enterprise Linux Server: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 5.0 only; version 6.0 only; version 7.0 only

Published 2018-06-11. Last modified 2026-06-17.