cbcvebase.
CVE-2016-2806
published 2016-04-30

CVE-2016-2806: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a…

high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianfirefox< firefox 46.0-1 (sid)firefox 46.0-1 (sid)
debianfirefox-esr< firefox 46.0-1 (sid)firefox 46.0-1 (sid)
mozillafirefox<= 45.0.2
mozillafirefox
mozillafirefox>= 0 < 46.0+build5-0ubuntu0.14.04.246.0+build5-0ubuntu0.14.04.2
mozillafirefox>= 0 < 46.0.1+build1-0ubuntu0.14.04.346.0.1+build1-0ubuntu0.14.04.3
mozillafirefox>= 0 < 46.0+build5-0ubuntu0.16.04.246.0+build5-0ubuntu0.16.04.2
mozillafirefox>= 0 < 46.0.1+build1-0ubuntu0.16.04.246.0.1+build1-0ubuntu0.16.04.2
opensuseleap
opensuseopensuse
opensuseopensuse
suselinux_enterprise

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH