cbcvebase.
CVE-2016-1935
published 2016-01-31

CVE-2016-1935: Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code…

PriorityP346high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
5.15%
91.5th percentile
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.

Affected

16 ranges
VendorProductVersion rangeFixed in
mozillafirefox<= 43.0.4
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox
mozillafirefox>= 0 < 44.0.1+build2-0ubuntu0.14.04.144.0.1+build2-0ubuntu0.14.04.1
mozillafirefox>= 0 < 44.0+build3-0ubuntu0.14.04.144.0+build3-0ubuntu0.14.04.1
mozillathunderbird>= 0 < 1:38.6.0+build1-0ubuntu0.14.04.11:38.6.0+build1-0ubuntu0.14.04.1
opensuseleap
opensuseopensuse
opensuseopensuse
oraclelinux
oraclelinux
oraclelinux

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.