CVE-2016-2805
published 2016-04-30CVE-2016-2805: Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption…
PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
4.65%
90.7th percentile
Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | >= 0 < 1:38.8.0+build1-0ubuntu0.14.04.1 | 1:38.8.0+build1-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:38.8.0+build1-0ubuntu0.16.04.1 | 1:38.8.0+build1-0ubuntu0.16.04.1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-683q-h46v-73wp: Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38
ghsa_unreviewed·2022-05-17
CVE-2016-2805 [HIGH] CWE-119 GHSA-683q-h46v-73wp: Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38
Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
OSV
thunderbird vulnerabilities
osv·2016-05-19·CVSS 6.5
CVE-2016-2805 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect results in some circumstances, resulting in
cryptographic weaknesses. (CVE-2016-1938)
A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange in
NSS. A remote attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code. (CVE-2016-1978)
A use-after-free was discovered in PK11_Impo
OSV
CVE-2016-2805: Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38
osv·2016-04-30·CVSS 8.8
CVE-2016-2805 [HIGH] CVE-2016-2805: Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38
Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2016-05-19·CVSS 6.5
CVE-2016-1938 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Christian Holler, Tyson Smith, and Phil Ringalda discovered multiple
memory safety issues in Thunderbird. If a user were tricked in to opening
a specially crafted message, an attacker could potentially exploit these
to cause a denial of service via application crash, or execute arbitrary
code. (CVE-2016-2805, CVE-2016-2807)
Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSS
produce incorrect results in some circumstances, resulting in
cryptographic weaknesses. (CVE-2016-1938)
A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange in
NSS. A remote attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary
Red Hat
Mozilla: Miscellaneous memory safety hazards (rv:38.8) (MFSA 2016-39)
vendor_redhat·2016-04-26·CVSS 8.8
CVE-2016-2805 [HIGH] Mozilla: Miscellaneous memory safety hazards (rv:38.8) (MFSA 2016-39)
Mozilla: Miscellaneous memory safety hazards (rv:38.8) (MFSA 2016-39)
Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Debian
CVE-2016-2805: firefox - Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x befo...
vendor_debian·2016·CVSS 8.8
CVE-2016-2805 [HIGH] CVE-2016-2805: firefox - Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x befo...
Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2805 Mozilla: Miscellaneous memory safety hazards (rv:38.8) (MFSA 2016-39)
bugzilla·2016-04-25·CVSS 8.8
CVE-2016-2805 [HIGH] CVE-2016-2805 Mozilla: Miscellaneous memory safety hazards (rv:38.8) (MFSA 2016-39)
CVE-2016-2805 Mozilla: Miscellaneous memory safety hazards (rv:38.8) (MFSA 2016-39)
Mozilla developers fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
Christian Holler reported a memory safety problem that is fixed in Firefox ESR 38.8.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-39.html
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Christian Holler
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 5
arXiv
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
arxiv_fulltext·2022-01-16
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources
Roland Croft12,
M. Ali Babar12,
Li Li3
1 School of Computer Science, University of Adelaide, Adelaide, Australia, \roland.croft, ali.babar\@adelaide.edu.au
2 Cyber Security Cooperative Research Centre, Australia
3 Faculty of Information Technology, Monash University, Melbourne, Australia, \li.li\@monash.edu
## Abstract
Software Vulnerability (SV) severity assessment is a vital task for informing SV remediation and triage. Ranking of SV severity scores is often used to advise prioritization of patching efforts. However, severity assessment is a difficult and subjective manual task that relies on expertise, knowledge, and standardized reporting schemes. Consequently, different data sources that per
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00057.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0695.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1041.htmlhttp://www.debian.org/security/2016/dsa-3559http://www.debian.org/security/2016/dsa-3576http://www.mozilla.org/security/announce/2016/mfsa2016-39.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1035692http://www.ubuntu.com/usn/USN-2973-1https://bugzilla.mozilla.org/show_bug.cgi?id=1241731https://security.gentoo.org/glsa/201701-15http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00054.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00057.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0695.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1041.htmlhttp://www.debian.org/security/2016/dsa-3559http://www.debian.org/security/2016/dsa-3576http://www.mozilla.org/security/announce/2016/mfsa2016-39.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1035692http://www.ubuntu.com/usn/USN-2973-1https://bugzilla.mozilla.org/show_bug.cgi?id=1241731https://security.gentoo.org/glsa/201701-15
2016-04-30
Published