Vulnerability Description
The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of special characters in attribute values, a different vulnerability than CVE-2016-9909.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Html5Lib | Html5Lib | <= 0.99999999 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/12/06/5Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/12/08/8Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/95132Third Party AdvisoryVDB Entry
- https://github.com/html5lib/html5lib-python/commit/9b8d8eb5afbc066b7fac9390f5ec7Patch
- https://github.com/html5lib/html5lib-python/issues/11Vendor Advisory
- https://github.com/html5lib/html5lib-python/issues/12Vendor Advisory
- https://html5lib.readthedocs.io/en/latest/changes.html#b9Release Notes
- http://www.openwall.com/lists/oss-security/2016/12/06/5Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/12/08/8Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/95132Third Party AdvisoryVDB Entry
- https://github.com/html5lib/html5lib-python/commit/9b8d8eb5afbc066b7fac9390f5ec7Patch
- https://github.com/html5lib/html5lib-python/issues/11Vendor Advisory
- https://github.com/html5lib/html5lib-python/issues/12Vendor Advisory
- https://html5lib.readthedocs.io/en/latest/changes.html#b9Release Notes
FAQ
What is CVE-2016-9910?
CVE-2016-9910 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of special characters in attribute values, a different...
How severe is CVE-2016-9910?
CVE-2016-9910 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9910?
Check the references section above for vendor advisories and patch information. Affected products include: Html5Lib Html5Lib.