CVE-2016-1956

CWE-3998 documents8 sources
Severity
6.5MEDIUM
EPSS
0.3%
top 45.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 14

Description

Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

NVDmozilla/firefox44.0.2
Debianfirefox-esr< 45.0esr-1+3
NVDopensuse/leap42.1
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-f987-fmmg-p98m: Mozilla Firefox before 452022-05-14
CVEList
CVE-2016-1956: Mozilla Firefox before 452016-03-13
OSV
CVE-2016-1956: Mozilla Firefox before 452016-03-13

📋Vendor Advisories

3
Ubuntu
Firefox vulnerabilities2016-03-09
Red Hat
Mozilla: Linux video memory DOS with Intel drivers (MFSA 2016-19)2016-03-08
Debian
CVE-2016-1956: firefox - Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows...2016

💬Community

1
Bugzilla
CVE-2016-1956 Mozilla: Linux video memory DOS with Intel drivers (MFSA 2016-19)2016-03-08
CVE-2016-1956 (MEDIUM CVSS 6.5) | Mozilla Firefox before 45.0 on Linu | cvebase.io