An issue where a <select> dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. External References: https://www.mozilla.org/en-US/security/advisories/mfsa2016-89/#CVE-2016-9076
Acknowledgements: Name: the Mozilla project Upstream: Mats Palmgren
Statement: This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5, 6 and 7.