Skip to main content
HIGH

CVE-2016-9902

CVSS v3

7.5

HIGH

EPSS Score

1.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Technical details

Published
2018-06-11

Frequently asked questions

What is CVE-2016-9902?

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Is CVE-2016-9902 actively exploited?

Active exploitation of CVE-2016-9902 has not been confirmed. Its EPSS score was 1.3% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2016-9902?

CVE-2016-9902 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2016-9902 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key