Related Vulnerabilities: CVE-2016-9895  

Event handlers on marquee elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript.

Severity High

Remote Yes

Type Access restriction bypass

Description

Event handlers on marquee elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript.

AVG-106 firefox 50.0.2-1 50.1.0-1 Critical Fixed

14 Dec 2016 ASA-201612-15 AVG-106 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2016-94/#CVE-2016-9895