CVE-2016-1959 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Firefox
CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer12 documents7 sources
Severity
8.8HIGHNVD
EPSS
0.9%
top 24.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 13
Latest updateMay 17
Description
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
🔴Vulnerability Details
5📋Vendor Advisories
5💬Community
1Bugzilla▶
CVE-2016-1959 Mozilla: Service Worker Manager out-of-bounds read in Service Worker Manager (MFSA 2016-22)↗2016-03-08