CVE-2016-1959Improper Restriction of Operations within the Bounds of a Memory Buffer in Firefox

Severity
8.8HIGHNVD
EPSS
0.9%
top 24.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13
Latest updateMay 17

Description

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

Ubuntumozilla/firefox< 45.0+build2-0ubuntu0.14.04.1+2
NVDmozilla/firefox44.0.2
debiandebian/firefox< firefox 45.0-1 (sid)
debiandebian/firefox-esr< firefox 45.0-1 (sid)

🔴Vulnerability Details

5
GHSA
GHSA-72cx-7rj4-3mpc: The ServiceWorkerManager class in Mozilla Firefox before 452022-05-17
OSV
firefox regressions2016-04-19
OSV
firefox regressions2016-04-07
OSV
CVE-2016-1959: The ServiceWorkerManager class in Mozilla Firefox before 452016-03-13
OSV
firefox vulnerabilities2016-03-09

📋Vendor Advisories

5
Ubuntu
Firefox regressions2016-04-19
Ubuntu
Firefox regressions2016-04-07
Ubuntu
Firefox vulnerabilities2016-03-09
Red Hat
Mozilla: Service Worker Manager out-of-bounds read in Service Worker Manager (MFSA 2016-22)2016-03-08
Debian
CVE-2016-1959: firefox - The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote atta...2016

💬Community

1
Bugzilla
CVE-2016-1959 Mozilla: Service Worker Manager out-of-bounds read in Service Worker Manager (MFSA 2016-22)2016-03-08