Related Vulnerabilities: CVE-2016-9900  

External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of data: URLs. This could allow for cross-domain data leakage.

Severity High

Remote Yes

Type Information disclosure

Description

External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of data: URLs. This could allow for cross-domain data leakage.

AVG-106 firefox 50.0.2-1 50.1.0-1 Critical Fixed

14 Dec 2016 ASA-201612-15 AVG-106 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2016-94/#CVE-2016-9900