﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
8584	firefox 50.0.2 (was 50.0.1)	Pierre Labastie	ken@…	"New point version: security fix:
{{{
CVE-2016-9078: data: URL can inherit wrong origin after an HTTP redirect.

Description

Redirection from an HTTP connection to a data: URL assigns the referring
site's origin to the data: URL in some circumstances. This can result in
same-origin violations against a domain if it loads resources from malicious
sites. Cross-origin setting of cookies has been demonstrated without the
ability to read them.
Note: This issue only affects Firefox 49 and 50.
}}}"	enhancement	closed	high	8.0	BOOK	SVN	medium	fixed		
